Supply chain
β Supply Chain
Gemini Third-Party Breach (July 2024)
Primary Source βIncident Details
Crypto exchange Gemini discloses third-party data breach. Cryptocurrency exchange Gemini is warning it suffered a data breach incident caused by a cyberattack at its Automated Clearing House (ACH) service provider, whose name was not disclosed. The American crypto exchange began sending notices to impacted individuals a month ago, on June 26, 2024 but submitted a sample of the letters yesterday to the Attorney General’s Office in California. According to the notification, Gemini suffered a third-party data breach when an unauthorized actor breached its vendor’s systems between June 3 and June 7, 2024. Third-party company: Not disclosed Automated Clearing House (ACH) service provider.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed Automated Clearing House (ACH) service provider
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-07-01 Breach occurred
- 2024-07-26 Publicly disclosed