BlockFi confirms unauthorized access to client data hosted on Hubspot

Share This Post

As a third-party vendor for BlockFi, Hubspot stored user data such as names, email addresses and phone numbers, which has been historically used for conducting phishing attacks.

New Jersey-based crypto financial institution BlockFi confirmed a data breach incident via one of its third-party vendors, Hubspot. BlockFi’s proactive warning about the breach aims to deter the intentions of bad actors in repurposing the user data for fraudulent activities.

According to the announcement, the hackers gained access to BlockFi’s client data on Friday, Mar. 18, that were stored on Hubspot, a client relationship management platform:

“Hubspot has confirmed that an unauthorized third-party gained access to certain BlockFi client data housed on their platform.”

As a third-party vendor for BlockFi, Hubspot stored user data such as names, email addresses and phone numbers. Historically, bad actors have used such information for conducting phishing attacks and gaining access to accounts through user-provided passwords.

At the time of writing, BlockFi is supporting Hubspot’s investigation to gain clarity on the overall impact of the data breach. While the exact details of the breached data are yet to be identified and revealed, BlockFi reassured users by highlighting that personal data — including passwords, government-issued IDs and social security numbers — “were never stored on Hubspot.”

In addition, BlockFi has also confirmed that its internal system and client funds were not accessed and that the breach remains limited to the third-party vendor, Hubspot. 

The company further recommended four methods to help users protect their online presence from bad actors — good password hygiene, two-factor authentication (2FA), allowlisting trusted applications and vigilance against scammers.

On an end note, BlockFi acknowledged that time is of the essence and are expediting their investigations to identify the extent of the breach:

“Additional information will be emailed to all impacted clients in the coming days.”

Investors are advised to be wary of all company communication, especially that demand urgency in requesting/changing personal details including passwords and wallet addresses.

Related: Rare Bears Discord phishing attack nabs $800K in NFTs

On Friday, Mar. 18, the recently launched nonfungible token (NFT) project Rare Bears was attacked, resulting in a theft of nearly $800,000 in NFTs.

As Cointelegraph reported, the attacked was conducted by a hacker who posted a phishing link in the project‘s Discord channel, and eventually stole 179 NFTs.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

TON blockchain sees explosive 3,435% growth in daily active addresses over 2024

The Open Network (TON) blockchain has experienced a significant surge in its on-chain metrics in 2024, with trading volume, total value locked, active users, and daily transactions all growing

Solana Active Addresses Hit 75 Million As SOL Breaches $140

Solana (SOL) hit another record: Today, it has over 75 million monthly active addresses The surge speaks to growing popularity of the network, especially in areas like developer and user activity

Vitalik Buterin Drops A Rhythm At Singapore TOKEN2049: Speech Delivered In Song

Co-founder of Ethereum, Vitalik Buterin, created a scene – albeit in a fun way – at the TOKEN2049 conference in Singapore by not only offering analysis on Ethereum developments but also

Lightning Network-Focused Startup Lightspark Sets Its Sights on Latam

Lightspark hopes to enter Latin America’s cryptocurrency market through its partners in the region, including exchanges like Bitso and fintech institutions like Nubank Nicolas Cabrera,

Cryptoquant: Coinbase’s cbBTC Could Challenge Bitgo in Wrapped Bitcoin Market

This week, Cryptoquant researchers highlighted a new rivalry heating up in the wrapped bitcoin market, with Coinbase’s cbBTC stepping up to challenge Bitgo’s long-established reign

SEC seeks 4-month extension for fact discovery in Coinbase lawsuit

The US Securities and Exchange Commission (SEC) has requested a four-month extension to complete fact discovery in its lawsuit against Coinbase In a letter submitted to Judge Katherine Polk Failla on