News

FSOCIETY Threatens Massive Bitfinex Data Leak: 400,000 Users At Risk

Key Points:

  • FSOCIETY threatens to leak Bitfinex user data.
  • Bitfinex CTO suggests leak origin is multiple crypto breaches.
  • Leaked list suspected as a scheme for dubious ads.
Bitfinex data leak allegedly by FSOCIETY includes 2.5TB of exchange data and 400K users’ details. Bitfinex CTO responded, raising questions about the leak’s origin.

The ransomware group, FSOCIETY, alleges to have gathered 2.5TB of Bitfinex exchange data, and personal details of 400,000 users.

Bitfinex Data Leak: Ransomware Group FSOCIETY’s Threats

They’ve threatened to leak users’ Know Your Customer (KYC) data unless their demands are met. A user authenticated a password from the leaked data, as per Shinoji Research.

FSOCIETY has uploaded a page on their onion site with links to a text file containing a partial dump of usernames and plaintext passwords. However, several accounts, including those associated with known trading firms like Alameda Research, were not in the list.

The group has threatened to leak all KYC data if their demands are not met, suggesting they have access to all KYC records since the company’s inception.

Analysis of Leaked Accounts and Bitfinex’s Response

A list of email domains from the leak primarily includes public domains, with the exception of coinfarm.co.za, suggesting the hacker may have intentionally excluded corporate accounts.

Bitfinex CTO Paolo Ardoino responded that only 5,000 of the 22,500 leaked emails match Bitfinex users, suggesting the hacker likely compiled a database from various crypto breaches.

Paolo noted that Bitfinex’s KYC system has heavy rate limiting, and passwords are not stored in plaintext, raising questions about the leak’s origin.

Assuming Bitfinex’s claims are true, most of the leaked accounts are heavily present on the HaveIBeenPwned website, with many logins traced back to the Coinmarketcap breach. It’s possible the list was reverse-engineered by using breached passwords on BitFinex, but the motivation is unclear.

Interestingly, the list is not for sale but is freely available on the hacker’s site, and Bitfinex wasn’t extorted. This raised suspicions of a potential scheme to charge for a fake KYC database. However, it appears F Locker, associated with FSOCIETY, is using the leaks to advertise dubious investments.

Thana

I am a news editor at Coincu, where I produce daily editorial packages and manage the knowledge and review article sections. Before journalism, I earned a Bachelor's degree in Global Logistics and Supply Chain Management from Northampton University and studied news journalism at Press Association Training.

Recent Posts

4 Emerging Cryptos Poised for Success in 2024

The crypto scene is constantly evolving, and certain currencies show significant promise for the upcoming…

2 hours ago

5 Altcoins Under $1 That Can Make Millionaires This Crypto BullRun

While some altcoins like PEPE, XRP, ONDO, and PYTH may not show significant short-term growth,…

2 hours ago

Ripple Trading Volume Increases 40% Quarterly Amid Ongoing SEC Lawsuit

Ripple Trading Volume Increases 40% Quarterly Amid Ongoing SEC Lawsuit

6 hours ago

Notcoin First Campaigns Prepared to Launch Next Week

Notcoin first campaigns will be launched next week, offering rewards but cautioning against unstaking.

7 hours ago

LayerZero Sybil Self-report Phase Is Now Ended With Over 800,000 Fraudulent Addresses

LayerZero Labs wraps up LayerZero sybil self-report and identifies 803,093 potential fraudulent addresses.

7 hours ago

Controversial Coinbase Outage Identified As Error Related To The Coinbase Card

The Coinbase outage was attributed to an error in the Coinbase Card reward service, causing…

8 hours ago

This website uses cookies.