{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef"},"incident":{"title":"Social engineering of a cloud ops employee preceded BitoPro's $11.5M theft","date":"2025-05-08","date_precision":"day","victim_org":"BitoPro","sector":"Cryptocurrency","country":"Taiwan","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":11500000,"loss_note":"About $11.5 million in suspicious withdrawals, disclosed publicly on June 3, 2025. BitoPro said reserves were sufficient and user functions were unaffected.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), attributed by BitoPro","summary":"Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.","how_it_worked":"BitoPro described the entry point only as social engineering against a cloud operations employee and did not disclose the specific channel or pretext used; the vector is recorded here as targeted phishing on that basis and the channel remains unconfirmed. Malware planted on the employee's device let the attackers hijack AWS session tokens, which sidestepped multi-factor authentication entirely because a live session had already satisfied it. Holding valid session tokens, they took control of BitoPro's cloud infrastructure and used their command server to inject scripts into the hot wallet system while a scheduled wallet upgrade and asset transfer was in progress. The malicious withdrawals were timed and shaped to mimic the legitimate migration traffic around them.","lessons":"Binding cloud session tokens to device posture and network origin, so a stolen token is unusable elsewhere, plus freezing automated wallet operations during manual migrations, would have denied both halves of this attack.","confidence":"Reported","sources":[{"title":"BitoPro exchange links Lazarus hackers to $11 million crypto heist","url":"https://www.bleepingcomputer.com/news/security/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/","publisher":"BleepingComputer"},{"title":"Taiwanese crypto exchange BitoPro confirms estimated $11.5 million hack","url":"https://fortune.com/crypto/2025/06/03/taiwanese-crypto-exchange-bitopro-confirms-hack/","publisher":"Fortune"}],"entry_type":"incident","slug":"2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef"}}