[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fy0z499a31sh4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825150","Coinmama","Coinmama Data Breach","coinmama","coinmama.com","2017-08-03T00:00:00.000Z","2019-08-30T20:53:29.000Z","2026-07-27T16:11:12.556Z","Verified breach record","https:\u002F\u002Fdatabreaches.net\u002F2019\u002F02\u002F16\u002Fmajor-crypto-brokerage-coinmama-reports-450000-users-affected-by-data-breach\u002F",[15,17],"https:\u002F\u002Fwww.coinmama.com\u002Fblog\u002Faccount-security-faq",478824,"known",null,"unknown","High",[24,25,26],"Email addresses","Passwords","Usernames","\u003Cp>The Coinmama data breach is a verified incident from August 2017 that affected Coinmama accounts used for cryptocurrency trading. The confirmed main scope is 478,824 unique email accounts. The incident became visible in February 2019, and the time it was added to the verified list is tracked as August 30, 2019. The affected data groups are email addresses, usernames, and passwords stored in MD5 WordPress hash format. Therefore, the risk is not limited to old Coinmama accounts; if the same password was used for another cryptocurrency, email, payment, or social media account, the possibility of account takeover continues.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data categories are email addresses, usernames, and passwords. The password field should be treated not as plain text passwords but as password data stored in MD5 WordPress hash format. MD5-based hashes are considered weak for modern password protection; short, predictable, or reused passwords can be cracked by attackers. If the same email and password remained valid on a cryptocurrency exchange, wallet, email inbox, bank, payment service, or social media account, an old breach could affect today's financial security.\u003C\u002Fp>\n\u003Cp>Username and email address provide sufficient context for fake investment, account verification, wallet recovery, or support messages targeting cryptocurrency users. Since a Coinmama account can be associated with depositing money or purchasing crypto, attackers may assume that the target could own digital assets. Phone number, physical address, payment card, official ID, wallet address, transaction history, or balance data in Coinmama data are not among the verified data categories. Risk transfer should be limited only to proven fields.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>For the Coinmama incident, the LeakData scope should be kept as 478,824 unique email accounts. The incident date should be tracked as August 3, 2017, and the verified addition time should be monitored as August 30, 2019. Although around 450,000 emails and hashed password entries appeared in the announcements from February 2019, the confirmed number of main accounts is kept as 478,824. This difference may arise due to duplicates, the verification process, and the unique email account count; the value presented to the user should be consistent with the scope of unique accounts.\u003C\u002Fp>\n\u003Cp>The scope is limited to Coinmama account data only. The presence of other brands in a wider wave of data sales does not justify adding data categories from different platforms to this record. Payment card, bank account, ID document, address, phone, crypto wallet private key, transaction list, or balance information should not be included among the proven fields for this incident. This limit prevents unnecessary panic due to the cryptocurrency context and directs the user toward the real risks, such as password reuse, account takeover, and targeted phishing.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they use on their Coinmama account on other accounts as well. People who use cryptocurrency accounts generally maintain the same identity across their email account, exchange account, wallet application, payment method, and social media account. The combination of email and username gives attackers the opportunity to create an account list. If the password hash can be cracked, this password can be tried on different services and the user's digital asset ecosystem can be targeted.\u003C\u002Fp>\n\u003Cp>Cryptocurrency investors, people who no longer use their old accounts, and users who open accounts on multiple exchanges with the same email address should be especially careful. In this situation, even if the wallet private key or balance information is not verified, attackers can mark the person as a crypto user. Fake customer support, urgent account verification, withdrawal warning, tax notification, or wallet recovery messages may appear more convincing in this context. A positive match still requires security action even though the old account has been closed.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>A user with an email address in the Coinmama database should first make sure that the old password used in their Coinmama account is not valid for any other account. If the same or a similar password has been used for email, cryptocurrency exchange, wallet, payment, bank, social media, or work accounts, a separate, long, and hard-to-guess password should be set for each account. Using a password manager reduces the risk of reuse. Maintaining the old password pattern with minor changes should not be considered secure.\u003C\u002Fp>\n\u003Cp>Two-factor authentication should be enabled on the email account and all accounts associated with cryptocurrency. Where possible, app-based authentication or a hardware security key should be preferred. When unexpected withdrawal notifications, wallet recovery requests, investment opportunities, account verification messages, or support calls are received, they should be checked through the official app or website without clicking any links. If a suspicious session is seen, sessions should be closed, recovery emails should be reviewed, and reused passwords should be completely changed.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Coinmama breach shows that identity information used in cryptocurrency accounts can still carry high risk even years later. Users should avoid reusing passwords across cryptocurrency, email, bank, payment, and social media accounts. Old exchange accounts should be regularly reviewed, and unused accounts should be closed or isolated with unique passwords and strong multi-factor protection. Since email addresses and usernames do not change for long periods, old breach data can be reused in new phishing attempts.\u003C\u002Fp>\n\u003Cp>The key lesson for service providers is to protect password hashes with modern and costly password storage methods, complete user notifications without delay, and clearly indicate which data fields are unaffected. In the context of cryptocurrency, fields such as payment, identity, and wallet data are very sensitive, so unverified fields should not be included in the scope of the incident. Coinmama's risk communication should remain focused on account security through email, username, and MD5 WordPress password hashes.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>As a result of the registration check for the Coinmama breach, it shows whether the entered email address is found in this verified dataset. If the result is positive, the email address, username, and password hash should be considered at risk. If the result is negative, it only indicates that no match was found in this specific dataset; this does not prove that the person is not involved in other cryptocurrency platforms or other data breaches. Keeping dates accurate is important to avoid confusing the event date with the verified addition date.\u003C\u002Fp>\n\u003Cp>The correct action is to completely abandon the old password, change all reused passwords, secure the email account with strong multi-factor protection, and be cautious of cryptocurrency-themed fake support or investment messages. The user should also check exchange, wallet, payment, and social media accounts opened with the same email and username. These steps reduce the risk that a 2017 data breach could turn into financial account takeover or targeted phishing today.\u003C\u002Fp>","","Coinmama Data Breach (478.8 Thousand Reported Records)","Coinmama Data Breach. 478.8 Thousand reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcoinmama_com.webp",false,{"name":7,"sector":34,"country":35,"website":10,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":20},"Cryptocurrency brokerage","Israel"]