Transak Data Breach Via Stormous Ransomware Group
Notice: This page is a freshly imported case study from an original repository. While the original content had a similar format, some sections may not have been fully completed. Please help fill in any empty sections or any missing information you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
Transak offers a gateway between cryptocurrency and fiat payment methods. They are widely integrated in services such as MetaMask and CoinBase wallet. In late October, one of their employees suffered a data breach and their access to the third party KYC provider was compromised. This exposed the private information from tens of thousands of customers including names, date of birth, identification documents, and proof of liveness videos. They've issued a public apology, and as of yet the information doesn't appear to have been used.[1][2][3][4][5][6][7][8][9][10]
About Transak
"Enable users to buy or sell crypto from your app. Available across 170 cryptocurrencies on 75+ blockchains via cards, bank transfers and other payment methods in 162 countries."
"Transak is a developer integration toolkit that enables you as an app developer to onboard your users to buy/sell crypto in any blockchain app, website or web plugin.
With Transak you can onboard mainstream users into your dApp, protocol, game or wallet app and also increase your revenue. We handle all of the KYC, regulation & compliance, fiat payment methods, and crypto coverage.
Whether you're just starting your project or a large established firm looking for a fiat on-ramp or off-ramp, integrating and customising Transak is an easy process. The simplest technical integrations can be done in just 5 minutes."
"Transak, a Miami-based fiat-to-crypto payment gateway used by Metamask, Trust Wallet, Coinbase, Ledger, among other blockchain platforms, disclosed on Monday it suffered a data breach affecting 1.14% of its users."
The Reality
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
Date | Event | Description |
---|---|---|
October 20th, 2024 1:43:00 PM MDT | Dark Web Informer Tweet | Dark Web Informer posts about the breach online. |
October 21st, 2024 9:46:36 AM MDT | The Block Article | Article published by The Block shares additional details on the ransomware attack. The Stormous ransomware group has claimed responsibility. |
October 21st, 2024 10:21:09 PM MDT | ChainCatcher Article | ChainCatcher publishes an article about the breach. |
Technical Details
"According to on-chain investigator ZachXBT, the crypto payment service provider Transak recently fell victim to a ransomware attack. Transak reported that the incident occurred when an attacker accessed an employee's laptop without authorization through a sophisticated phishing attack. The attacker used the stolen credentials to log into the system of a third-party KYC vendor used for document scanning and verification services. As a result, the attacker gained access to specific user information stored in the vendor’s dashboard."
Total Amount Lost
"Stormous claims to have stolen 300 gigabytes of data from Transak, including sensitive documents such as IDs, addresses, financial statements and selfies used during the know-your-customer onboarding process."
No funds were lost.
Immediate Reactions
"We have recently identified that an attacker gained unauthorized access to one of our employee’s laptop through a sophisticated phishing attack. Using the compromised credentials, the attacker was able to log in to the system of a third-party KYC vendor that we use for document scanning and verification services. As a result, the attacker gained access to specific user information stored within the vendor’s dashboard."
"After our thorough checks, we can confidently confirm that no financially sensitive information, including email addresses, phone numbers, passwords, credit card details, Social Security Numbers, or any other financial data, was compromised in any way. Our financial systems’ security measures remain robust, and we continue to protect all critical data, ensuring the highest level of privacy and security for our users.
Transak operates as a fully non-custodial platform, meaning that user funds—whether fiat or cryptocurrency—are never held by us and therefore remain completely secure and unaffected by any such attack. Users retain full control over their assets at all times, ensuring that no funds are ever at risk.
We deeply empathise with how frustrating and disappointing this must be for the affected users. Our top company priority is taking action to protect users and fix any vulnerabilities to ensure nothing like this ever happens again."
"We have engaged one of the industry’s leading cybersecurity firms, along with top forensic experts, to conduct an in-depth investigation. Their expertise has allowed us to quickly assess the situation, identify the breach points, and immediately halt any further unauthorized access.
We continue to invest heavily in data security, system security, compliance, and reliability.
We are reaching out to the affected users. Please note that this attack affected 1.14% of the total users of Transak, and if we do not email you, then you have not been affected.
We are also reaching out to any affected partners to share transparency on how they were affected.
We are improving training, software, and systems to prevent phishing and social engineering attacks on our team members and to limit any access or damage if an attack occurs.
We have informed relevant data protection authorities, including the Information Commissioner’s Office (ICO) in the UK and other regulators across the EU and US, with reviews for other countries in progress."
Ultimate Outcome
"The notorious Stormous ransomware gang has claimed responsibility for the hack, posting some of the stolen records on its site. The ring also recently disclosed it was behind the breach of Fractal ID—a decentralized identity system that provides identity verification and provisioning for Web3 projects—in July. Fractal co-founder Julian Leitloff denies Stormous was behind the hack."
"In an update to its disclosure on Tuesday, Transak said that ID documents including passports and driver's licenses were also pilfered."
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
"Currently, there is no indication that the data has been misused. However, we advise affected users to remain vigilant and monitor for suspicious activity. We will be reaching out to affected users with advice and resources on protecting themselves from potential misuse of the information and offering resources such as identity monitoring services."
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ Transparency and Action: Transak’s Response to a Recent Security Incident | Transak (Accessed Nov 13, 2024)
- ↑ Fiat On/Off Ramp Developer Integration for Web3 & Crypto Apps | Transak (Accessed Nov 13, 2024)
- ↑ What is Transak? (Accessed Nov 13, 2024)
- ↑ ZachXBT: Transak recently suffered a ransomware attack, resulting in the leakage of some user information - ChainCatcher (Accessed Nov 13, 2024)
- ↑ https://www.theblock.co/post/322263/transak-discloses-data-breach-affecting-over-57000-users-stormous-ransomware-gang-claims-responsibility (Accessed Nov 13, 2024)
- ↑ Transak has Been Claimed a Victim by STORMOUS Ransomware (Accessed Nov 13, 2024)
- ↑ Transak was hacked. Attacker takes responsibility (Accessed Nov 13, 2024)
- ↑ @DarkWebInformer Twitter (Accessed Nov 13, 2024)
- ↑ @DarkWebInformer Twitter (Accessed Nov 13, 2024)
- ↑ Transak discloses data breach affecting over 57,000 users, Stormous ransomware gang claims responsibility - AICoin (Accessed Nov 13, 2024)