Skip to content
NetarxImpact Database
SIM SwapNo AI reportedConfirmed

SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data

Kroll · Professional Services · United States · August 19, 2023

What happened

Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.

How the deception worked

The attacker convinced T-Mobile to port a Kroll employee's number to a SIM they controlled, a transfer carried out by a mobile carrier representative acting on a fraudulent request. Once the number was theirs, SMS-based authentication codes for the employee's accounts arrived on the attacker's device, letting them reset access and reach the claimant files Kroll held as bankruptcy administrator. The victims were bankrupt crypto platforms' creditors, a population whose names and contact details are immediately monetisable through targeted phishing about their claims, and several such phishing waves followed the breach.

The control that would have caught it· our reading, not a claim from the sources

Remove SMS from the authentication path entirely for staff handling sensitive data, and place carrier-level port-out locks on corporate mobile numbers.

Sources (2)

  1. Kroll Employee SIM-Swapped for Crypto Investor Data
    Krebs on Security·krebsonsecurity.comOpen ↗
  2. T-Mobile SIM-swapping attack on Kroll employee caused crypto platform data breach
    The Record·therecord.mediaOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.