Supply chain
β Supply Chain
FTX Third-Party Breach (September 2023)
Primary Source βIncident Details
Kroll data breach exposes info of FTX, BlockFi, Genesis creditors. Multiple reports on social media warn of a data breach at financial and risk advisory company Kroll that resulted in exposing to an unauthorized third-party the personal data of some credit claimants. Kroll, who is facilitating claims for insolvent companies FTX , BlockFi , and Genesis Global Holdco , has confirmed that one of its employees was the victim of a SIM-swapping attack. Hackers stole the Kroll employee’s phone number and used it to gain access to some files with personal data of bankruptcy claimants. Third-party company: Kroll Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Kroll Inc.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-09-01 Breach occurred
- 2023-08-25 Publicly disclosed