[BreachExchange] Korean bitcoin exchange Bithumb under attack as employee computer hacked

Audrey McNeil audrey at riskbasedsecurity.com
Mon Jul 10 20:13:06 EDT 2017


http://gizpress.com/2017/07/08/korean-bitcoin-exchange-
bithumb-under-attack-as-employee.html

Bithumb performs large exchanges of Bitcoins and Ethereums in #South Korea.

The state-run Korea Internet & Security Agency has teamed up with the Korea
Communications Commission to investigate the hack, according to the Yonhap
news agency.

According to the reports, the attack happened on June 29 (22:00 local
time), and the hacker managed to compromise the personal computer of a
Bithumb employee and stole personal details of 31,800 members, around three
percent of the user base. It is the world's fourth-largest bitcoin
exchange. The aftermath constituted a loss of billions of won that were
withdrawn from the accounts of customers. For context, 1 billion won is
about $870,000, or £670,000.

If had indeed been stolen from Bithumb customers, this hack is just another
reason why some argue that it may not be wise to entrust your funds to a
third party.

Japan, which previously accounted for barely 1% of total bitcoin trading
volume, is now the second largest market, representing over 30% of the
world's bitcoin trading volume. This gadget had no connection to exchange's
servers, digital wallets, and internal network.

They got their full names, e-mail addresses, phone numbers, the South
Korean authorities have revealed.

South Korean lawmakers are preparing a set of bills to give
cryptocurrencies such as Bitcoin and Ethereum, legal grounds in the
country, a move aimed at protecting locals from potential risks in
transactions.

Some Bithumb users were victims of "voice phishing", where someone phoned
them up saying they worked for Bithumb and scammed them out of funds,
according to BraveNewCoin.

One of the measures aims to revise the Electronic Financial Transactions
Act. This number of victims accounts for around 3% of Bithumb database of
clients. Since then, around 100 customers notified the National Police
Agency of being damaged by this hacking operation.

In an official notice, Bithumb stated that the "compensation for personal
information leakage cases has been decided". "For those who have suffered
additional damage due to this incident, as soon as the amount of damages is
confirmed, we will reimburse the entire amount of damages", the company
added. However, the Herald reported on Monday that about 100 victims are
expected to file a class action lawsuit against Bithumb.

Ethereum currency is a digital currency, similar to Bitcoin, that can be
used to pay for items.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.riskbasedsecurity.com/pipermail/breachexchange/attachments/20170710/9ca25790/attachment.html>


More information about the BreachExchange mailing list