A hacker who broke into Ethereum.org is said to be selling three popular hardware databases, Ledger, Trezor, and KeepKey. These three databases together contain the names, addresses, telephone numbers and emails of more than 80,000 users, however, the account password is not included in this information. The hacker recently added the SQL database of the BnkToTheFuture online investment platform to his sales list.
Cyber ββattack on Ledger and Trezor databases
On May 24, the Cybercrime Monitoring website saw the new list provided by the hacker, which included databases of top hardware providers. The hacker claims to have account information for approximately 41,500 Ledger users, more than 27,100 Trezor users and 14,000 KeepKey customers. Chat reports posted on Twitter show that the data was stolen through vulnerabilities on Shopify's popular e-commerce website.
Hackers infiltrate other platforms
In addition to hacking into the emails of two cryptocurrency tax platforms, the hacker now claims to have access to the database of 18 virtual currency exchanges and chat forums. These databases include the Korean Corbit SQL with 4500 users, three databases of the Mexcican Bitso trading platform and complete account information, including the passwords of the Blockcypher, Nimirum and Plutus blockchain platforms. The hacker revealed that he was only interested in special offers and said, "Don't offer me a small dollar, only big money is allowed!"
KYC platforms are a good weakness for hackers
Last week, BlockFi reported an infiltration of the Sim-swap attack that revealed the full names of customers, email addresses, dates of birth and physical addresses. Customer assets, however, were not affected. In late April, Etana, a cloud service company that provides services to Kraken Exchange, also came across information that did not steal any funds from customers.