Supply chain β›“ Supply Chain

FTX Third-Party Breach (September 2023)

πŸ“… 2023-09-01 🏒 Kroll Inc.
Primary Source β†—

Incident Details

Kroll data breach exposes info of FTX, BlockFi, Genesis creditors. Multiple reports on social media warn of a data breach at financial and risk advisory company Kroll that resulted in exposing to an unauthorized third-party the personal data of some credit claimants. Kroll, who is facilitating claims for insolvent companies FTX , BlockFi , and Genesis Global Holdco , has confirmed that one of its employees was the victim of a SIM-swapping attack. Hackers stole the Kroll employee’s phone number and used it to gain access to some files with personal data of bankruptcy claimants. Third-party company: Kroll Inc..

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Kroll Inc.
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-09-01 Breach occurred
  2. 2023-08-25 Publicly disclosed