{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da"},"incident":{"slug":"2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da","title":"SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data","date":"2023-08-19","date_precision":"day","year":2023,"victim_org":"Kroll","sector":"Professional Services","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.","how_it_worked":"The attacker convinced T-Mobile to port a Kroll employee's number to a SIM they controlled, a transfer carried out by a mobile carrier representative acting on a fraudulent request. Once the number was theirs, SMS-based authentication codes for the employee's accounts arrived on the attacker's device, letting them reset access and reach the claimant files Kroll held as bankruptcy administrator. The victims were bankrupt crypto platforms' creditors, a population whose names and contact details are immediately monetisable through targeted phishing about their claims, and several such phishing waves followed the breach.","lessons":"Remove SMS from the authentication path entirely for staff handling sensitive data, and place carrier-level port-out locks on corporate mobile numbers.","confidence":"Confirmed","sources":[{"title":"Kroll Employee SIM-Swapped for Crypto Investor Data","url":"https://krebsonsecurity.com/2023/08/kroll-employee-sim-swapped-for-crypto-investor-data/","publisher":"Krebs on Security"},{"title":"T-Mobile SIM-swapping attack on Kroll employee caused crypto platform data breach","url":"https://therecord.media/sim-swap-attack-caused-crypto-breach","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da"}}