• About Us
  • Privacy Policy
  • Contact Us
Subscribe
BitcoinCryptos - News About Bitcoin & Cryptos
  • Home
  • Bitcoin
  • Ethereum
  • Dogecoin
  • Litecoin
  • Cryptocurrency
  • Blockchain
  • Regulation
  • Market
  • Prices
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Dogecoin
  • Litecoin
  • Cryptocurrency
  • Blockchain
  • Regulation
  • Market
  • Prices
No Result
View All Result
BitcoinCryptos
No Result
View All Result
Home Bitcoin

Data Leak At Unchained Capital, NYDIG, Swan & BlockFi. At The Same Time

March 21, 2022
in Bitcoin
0
Data Leak At Unchained Capital, NYDIG, Swan & BlockFi. At The Same Time
Share on FacebookShare on Twitter


What do Unchained Capital, NYDIG, Swan Bitcoin, and BlockFi have in common? Third-party providers. Even though the four companies confronted the data leak head-on and admitted their wrongs, the compromised security was someone else’s. Luckily, the data the bad actors stole was not critical financial information, but marketing-driven personal info. Terrible, to be sure, but not as terrible as it could have been.

Related Reading | BlockFi Survey Says 33% Of Women Plans To Buy Crypto This Year

All the companies – Unchained Capital, NYDIG, Swan Bitcoin, and BlockFi – released press releases with mea culpas. Let’s explore them to see what we learn from them.

What Does Unchained Capital Have To Say For Themselves?

The company’s CEO and Co-Founder, Joseph Kelly, addressed the problem through a letter in the Unchained Capital blog. Kelly let them know that “a security incident that occurred at one of the vendors we previously used for email marketing.” Also, that “there is no impact whatsoever to Unchained Capital’s systems.” Then, he described what happened:

“ActiveCampaign (“AC”), a third-party email marketing provider that Unchained Capital used until early in 2022, was the subject of a social engineering attack last week. This attack occurred after Unchained Capital had closed its AC account and requested that all data be purged.”

Notice that the provider, ActiveCampaign, is not the same as in the following three cases. Unchained Capital makes clear that none of this was stolen: “client profile information containing personally identifiable information (e.g. addresses, SSN, DOB, IDs, phone numbers used in our KYC process), bank account numbers, passwords, bitcoin addresses, bitcoin balances, loan balances, trading activity, vault statements, loan statements.”

On the other hand, the “data included: email addresses, usernames, account status (active/inactive) and whether the client had an active vault or loan with Unchained Capital (yes or no).” And, for some unlucky users, “their name, email address, and IP address”

What should compromised users do?

“It is always important that our clients be diligent about confirming all communications and any requests that appear to come from Unchained Capital. Given the data leak, clients should be on high alert for any spear phishing attempts. Be especially careful about clicking on any links.”

BTCUSD price chart for 03/21/2022 - TradingView

BTC price chart for 03/21/2022 on Oanda | Source: BTC/USD on TradingView.com

Swan Bitcoin, NYDIG, And BlockFi Point At Hubspot

We could ensemble the same press release that Unchained Capital put out using these three companies’ communications. The difference is, they point at Hubspot. A similar company to ActiveCampaign, but, a different company altogether. Is there any more to this story? Is someone targeting these companies?

Let’s see what we can learn from Swan Bitcoin’s letter. Their description of the situation namedrops Hubspot four times in the first paragraph:

“On March 18th, 2022 one of our third-party vendors, Hubspot, confirmed that a bad actor gained access to Hubspot data after a Hubspot employee account was compromised. Hubspot notified us that the compromise was to a portion of their platform that included Swan client data.”

Yesterday, Hubspot, a third-party marketing vendor, confirmed a bad actor within their company gained access to Swan client marketing data.

Read Cory’s email to clients in the attached screenshots for details.

We’ll keep you updated. pic.twitter.com/qtXVk5AOW8

— Swan Bitcoin (@SwanBitcoin) March 19, 2022

They also described the size of the damage with comforting words “We use Hubspot for limited client communication and marketing data. We do not use Hubspot to store financial information, transactions, or other sensitive personal or financial information.” So, nothing to see here, right?

Let’s look at BlockFi, the company describes the situation in more dramatic terms. “To be clear, BlockFi’s internal systems and client funds are safeguarded and were not impacted. We can also confirm that BlockFi account passwords, government-issued ID numbers and social security numbers were never stored on Hubspot.”

Here are steps to protect your online presence from third-party bad actors: pic.twitter.com/tOKf16wOuf

— BlockFi (@BlockFi) March 19, 2022

And they don’t downplay the damage so much:

“As part of Hubspot being used for CRM and marketing purposes, BlockFi stored data that included name, email, and phone number for the majority of our clients. We are working with Hubspot as they continue their investigation to understand the full scope of impact.”

Neither does NYDIG, who ended their press release with a call to action for clients:

“To protect yourself, it is important that you exercise extra vigilance and care when reviewing or responding to emails, text messages, and phone calls, particularly those related to NYDIG.”

What Are Unchained Capital, Swan Bitcoin, NYDIG, And BlockFi Doing About It?

To answer this, we quote Swan’s Cofounder Yan Pritzker, who tweeted:

“We have been working round the clock since the incident with procedures including a data scrub, termination of further data to 3rd parties and complete audit. We will put out a comprehensive plan in the next week which will include moving away from using vendors for email.”

Startups rely on 3rd parties because it would be impossible to get a company off the ground if you build everything yourself. We chose vendors with extremely high standards. Hubspot had soc 2 type ii certification, for example. But it’s clearly time to take this in house.

— Yan Pritzker 🦢 (@skwp) March 20, 2022

And, since all the company’s responses have been similar, we hope they’re all doing something similar. However, a few burning questions remain. Were these companies targeted? Were the bad actors precisely looking for the information they got? Will we hear about these leaks in the future, connected to a bigger story? 

Related Reading | Bitcoin Firm NYDIG Gets $200m Injection from Morgan Stanley, Soros

If all of the companies would’ve been using just one service, that would be one thing. But both ActiveCampaign and Hubspot? On the same day? Targeting four bitcoin-related companies? There might be more to this story.

Featured Image by National Cancer Institute on Unsplash | Charts by TradingView





Source link

Related articles

Attendees At First New York City Crypto Summit Implore Mayor Adams To End The BitLicense

Attendees At First New York City Crypto Summit Implore Mayor Adams To End The BitLicense

May 21, 2025
Tribalism Is Not The Core Problem

Tribalism Is Not The Core Problem

May 21, 2025
Tags: BlockFiCapitalDataLeakNYDIGSwantimeUnchained
Share76Tweet47

Related Posts

Attendees At First New York City Crypto Summit Implore Mayor Adams To End The BitLicense

Attendees At First New York City Crypto Summit Implore Mayor Adams To End The BitLicense

May 21, 2025
0

Today, New York City hosted its first ever Crypto Summit. The event took place at Gracie Mansion, the mayor’s residence,...

Tribalism Is Not The Core Problem

Tribalism Is Not The Core Problem

May 21, 2025
0

The United States government stands mere months, if not weeks, from the passing of stablecoin legislation that will set the...

Magic Eden Partners With Spark To Bring Fast, Cheap Bitcoin Settlements

Magic Eden Partners With Spark To Bring Fast, Cheap Bitcoin Settlements

May 20, 2025
0

Magic Eden is integrating with Spark to improve Bitcoin trading by addressing issues like slow transaction times, high fees, and...

KindlyMD Shareholders Approve Merger With Bitcoin Treasury Company Nakamoto

KindlyMD Shareholders Approve Merger With Bitcoin Treasury Company Nakamoto

May 20, 2025
0

KindlyMD, Inc. has secured shareholder approval for its proposed merger with Nakamoto Holdings Inc., marking a major step toward becoming...

The Blockchain Group Secures €8.6 Million To Boost Bitcoin Strategy

The Blockchain Group Secures €8.6 Million To Boost Bitcoin Strategy

May 20, 2025
0

The Blockchain Group (ALTBG), listed on Euronext Growth Paris and known as Europe’s first Bitcoin Treasury Company, has announced a...

Load More

Leave a Reply

Your email address will not be published. Required fields are marked *

Argentina’s Milei shuts down task force investigating LIBRA scandal

Argentina’s Milei shuts down task force investigating LIBRA scandal

May 21, 2025
0

Argentine President Javier Milei has dissolved a task force established to investigate the fallout from LIBRA, the scandalous cryptocurrency project...

Ethereum Exchange Supply Hits Historic Low Below 4.9% — Is Price Breaking $3,000 Soon?

Ethereum Exchange Supply Hits Historic Low Below 4.9% — Is Price Breaking $3,000 Soon?

May 21, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure According to on-chain data from analytics platform...

Coinbase Faces Lawsuit Over Unauthorized Biometric Data Collection

Coinbase Faces Lawsuit Over Unauthorized Biometric Data Collection

May 21, 2025
0

Coinbase is facing a class-action lawsuit filed by a group of Illinois residents who allege the crypto exchange illegally collected...

‘Hawk tuah girl’ Haliey Welch says FBI probed her ‘memecoin disaster’

‘Hawk tuah girl’ Haliey Welch says FBI probed her ‘memecoin disaster’

May 21, 2025
0

Haliey Welch, better known as the “Hawk tuah girl,” says the Federal Bureau of Investigation briefly probed her after her...

SEC charges Unicoin and executives for alleged $100 million fraud

SEC charges Unicoin and executives for alleged $100 million fraud

May 21, 2025
0

The US Securities and Exchange Commission has charged crypto platform Unicoin and three of its executives, alleging they made false...

We have all the news related to the crypto market and we make sure to bring and publish all the updates as fast as we can.

Categories

  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Litecoin
  • Market
  • Regulation

Archives

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021

Newsletter

    • About Us
    • Privacy Policy
    • Contact Us

    © 2021 bitcoincryptos.com

    Please enter CoinGecko Free Api Key to get this plugin works.
    No Result
    View All Result
    • Home
    • Bitcoin
    • Ethereum
    • Dogecoin
    • Litecoin
    • Cryptocurrency
    • Blockchain
    • Regulation
    • Market
    • Prices

    © 2018 JNews by Jegtheme.