$0 USD

NOVEMBER 2022

GLOBAL

GEMINI

DESCRIPTION OF EVENTS

"Turn your money into crypto assets - The secure way to buy, sell, store, and convert crypto. Millions use Gemini to diversify their portfolios."

 

"Gemini currently has 13 million active users"

 

"Gemini currently has 13 million active users"

 

"A third-part vendor related to Gemini appeared to have suffered a data breach on or before Dec. 13. According to documents obtained by Cointelegraph, hackers gained access to 5,701,649 lines of information pertaining to Gemini customers’ email addresses and partial phone numbers. In the case of the latter, hackers apparently did not gain access to the full phone numbers, as certain numeric digits were obfuscated. After the news came to light, Gemini has since clarified in a blog post that the breach appeared to be "result of an incident at a third-party vendor" but also warned of ongoing "phishing campaigns" as a result of the data leak."

 

"The leaked database did not include sensitive personal information such as names, addresses and other Know Your Customer information. In addition, some emails were repeated in the document; thus, the number of customers affected is likely lower than the total rows of information."

 

"Some Gemini customers have recently been the target of phishing campaigns that we believe are the result of an incident at a third-party vendor. This incident led to the collection of Gemini customer email addresses and partial phone numbers. No Gemini account information or systems were impacted as a result of this third-party incident, and all funds and customer accounts remain secure."

 

"The worrying thing is that my (receiving) email address ONLY exists in my Gemini account and nowhere else. I setup custom email addresses for every service I use, and I only use my personal domain for a limited number of trusted accounts. I use Gmail and Yahoo accounts for risky or throw away accounts."

 

"I use email aliases so each online account has a specific email linked to it. This phishing attempt went to the email used by and only by my Gemini account. Thankfully I have no funds there but this was a complex phish and twitter has another example of an SMS-based Coinbase phishing attempt."

 

"The Gemini exchange also went briefly offline during the day after issues surrounding the data leak were brought to light. The exchange is fully functional at the time of publication [of a CoinTelegraph article]."

 

"Some Gemini customers have recently been the target of phishing campaigns that we believe are the result of an incident at a third-party vendor. This incident led to the collection of Gemini customer email addresses and partial phone numbers. No Gemini account information or systems were impacted as a result of this third-party incident, and all funds and customer accounts remain secure.

 

In light of these increased phishing campaigns, we are sharing security best practices with our customers."

 

""Not handled well." This was how one user described the revelations brought forth by Cointelegraph on Dec. 14 regarding the leak of 5.7 million Gemini customers’ email addresses and partial phone numbers. Shortly after publication, multiple users reached out to Cointelegraph alleging that the leak, which Gemini attributes to a “third-party incident,” happened much earlier than initially understood."

After a data breach, multiple Gemini users reported that they had received sophisticated phishing emails to their Gemini account email addresses. Many of the emails attempted to trick users into providing their seed phrase to upgrade their wallets to avoid losing their funds in anticipation of the Ethereum merge. Emails may have started as early as October 3rd, and the breach was finally reported on December 14th.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.