Skip to content

Cybersecurity Firm Kroll Hit by SIM-Swapping Attack, Sensitive Data Stolen

Kroll, a leading cybersecurity firm, has been targeted in a SIM-swapping attack. Personal data of bankruptcy claimants is at risk, and phishing emails have already been reported.

This is the poster where we can see mobiles and some text is there at the top.
This is the poster where we can see mobiles and some text is there at the top.

Cybersecurity Firm Kroll Hit by SIM-Swapping Attack, Sensitive Data Stolen

Cybersecurity firm Kroll has fallen victim to a SIM-swapping attack, resulting in the theft of sensitive user data from multiple cryptocurrency exchanges. The attack, which occurred on August 19, 2023, has put personal information of bankruptcy claimants in high-profile cases at risk.

The attack targeted a T-Mobile phone number belonging to a Kroll employee, granting access to files containing personal information of claimants in the matters of BlockFi, FTX, and Genesis. This data breach has led to phishing emails spoofing FTX, targeting individuals who received breach notices from Kroll today. Both BlockFi and FTX have disclosed data breaches this week due to the SIM-swapping attack.

Kroll, which specializes in managing cyber risk and investigating data breaches, has not publicly named the individuals behind the attack. To mitigate risks, users are advised to inventory their online accounts and reduce reliance on SMS for password resets and authentication where possible. This incident serves as a reminder to minimize reliance on mobile phone companies for security and to reduce the attack surface presented by employees using T-Mobile for wireless service.

The SIM-swapping attack against Kroll has highlighted the vulnerabilities of relying on mobile phone companies for security. With personal information of bankruptcy claimants at risk, users and organizations must take proactive steps to protect their data. As the investigation into the attack continues, the cybersecurity community awaits further details and potential recommendations to prevent similar incidents in the future.

Read also:

Latest