Hacker Steals Millions from Virtual Currency Exchange Bithumb

Robinson+Cole Data Privacy + Security Insider
Contact

A cyber-attack against–Bithumbone of South Korea’s largest cryptocurrency exchanges and one of the five largest in the world—has reaped access to the data of 30,000 users and drained their accounts in the process. Bithumb is one of the biggest ethereum exchanges by volume in South Korea, representing more than 44 percent of trading in that country.

The Korea Internet and Security Agency is investigating the incident that occurred on June 30 when an intruder obtained access to Bithumb’s system through the hacking of an employee’s home PC. The incident affected 3 percent of Bithumb’s users.

The data that was compromised in the incident included users’ names, mobile telephone numbers and email addresses. In addition, some users’ disposable password used in financial transactions was also compromised. This led to the draining of some of those users’ accounts.

The hackers used “voice phishing” (vishing), which is when the hacker directly contacts the company on the telephone, poses as an executive and tries to get information from an unsuspecting employee—including usernames, passwords and security codes or answers to security questions in order to gain access to the company’s system.

In this case, it is being reported that the attacker posed as an executive of Bithumb in a telephone call, claimed that suspicious activity was found on the account, and asked for the credentials so he could fix it. The victim complied and the hacker gained access to account information and thereafter drained multiple financial accounts of users.

Bithumb is offering to compensate victims and is continuing to investigate the incident.

The lesson is that hackers and criminals are very bold and using new techniques to steal. We talk a lot about email phishing and spear phishing, but vishing should not be overlooked. Employee education is important in alerting employees to these sophisticated techniques.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Robinson+Cole Data Privacy + Security Insider

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide