Bits of Gold says third-party breach exposed data tied to 200,000 customers
The Israeli broker says names, identity numbers, bank details and public wallet addresses may have been accessed, but funds, passwords and private keys were not.
By The Third AnglePublished 3 min read
Illustrative cybersecurity imagery for a report on a customer-data breach; the image does not depict Bits of Gold's systems. Photo: Unsplash · Unsplash License
Israeli crypto broker Bits of Gold says an unauthorized party accessed a supporting data-analytics system in a wider cyber incident. In its Aug. 16 customer notice, the company said personal information may have been exposed while customer funds and digital assets were not involved. CoinDesk reported that the incident affected data tied to roughly 200,000 customers.
The company said it blocked access and disconnected the affected system from its information sources after detecting the incident. It has notified relevant authorities and hired a specialist incident-response firm to investigate.
What may have been exposed
Bits of Gold's notice lists names, contact and identity details such as national ID numbers, email addresses and phone numbers, IP addresses, bank-account details and public cryptocurrency wallet addresses among the information that may have been accessible. It says there is no indication that the information has been used.
The notice says the incident did not involve customer funds, private keys, account passwords, full payment-card details, CVV codes or scans of identity documents. The company also says its services continue to operate normally.
The immediate risk is impersonation
Bits of Gold is warning customers to expect phishing, impersonation and suspicious messages that use the exposed details. It says customers should not provide passwords, verification codes or private keys, click unfamiliar links, or transfer money or digital assets because of an unsolicited contact.
The public record currently supports a customer-data exposure, not a wallet theft. The remaining questions are how many records were actually accessed, whether the third-party system was shared with other firms and what the incident investigation finds about the scope of the breach.