[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1ybnegg09h2jg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825151","cointracker","CoinTracker Data Breach","cointracker.io","2022-12-01T00:00:00.000Z","2022-12-12T08:55:48.000Z","2026-07-09T18:53:36.748Z","2026-07-18T23:47:50.199Z","Third party breach","https:\u002F\u002Fwww.cointracker.io\u002Fblog\u002Fsendgrid-data-breach",[15,17,18],"https:\u002F\u002Fdatabreaches.net\u002F2022\u002F12\u002F03\u002Fimportant-cointracker-security-update\u002F","https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Fcointracker-data-breach",1557153,"known",null,"unknown","Critical",[25,26],"Email addresses","Partial phone numbers","\u003Cp>The CoinTracker data breach record concerns the exposure of user email addresses associated with the cryptocurrency portfolio and tax tracking service through a third-party email service on December 1, 2022. This record is tracked across 1,557,153 affected accounts. The essence of the incident is the circulation of email addresses that could indicate that CoinTracker users are involved in crypto tax and portfolio tracking. Therefore, the risk is more targeted crypto-themed phishing and scam messages rather than direct financial data loss.\u003C\u002Fp>\n\u003Cp>The verified data classes are being tracked as email addresses and partial phone numbers. In its statement regarding the incident, CoinTracker noted that the leak did not originate from its main database, that it does not collect financial data or phone numbers, and that the observed phone fields did not come from its service. Therefore, two distinctions should be maintained when disclosing the record: a partial phone field can be tracked in breach datasets; however, the actual verified user impact on CoinTracker's side is limited to email addresses. Crypto assets, portfolio balances, wallet keys, tax reports, or transaction histories are not within the verified scope of this record.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The primary data type in the CoinTracker record is the email address. The email address provides a strong signal that the user may be associated with a crypto portfolio or tax tracking service. This information can be used for fake tax reports, portfolio updates, crypto wallet verification, exchange linking, airdrops, security alerts, or account confirmation messages. Since users in the crypto space are often seen as high-value targets, even just an email address can be valuable to attackers.\u003C\u002Fp>\n\u003Cp>The partial phone number field should be interpreted more carefully. Although this field has been reported to appear in datasets, CoinTracker has stated that it does not collect phone numbers and that these fields do not originate from its service. Partial phone information cannot be used as directly as a full number; however, when combined with other datasets, it can facilitate the creation of a user profile. In this case, since the password, crypto wallet key, portfolio balance, or financial account data were not verified, the risk of targeted messaging emerges rather than direct asset loss.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of verified affected accounts for this record is 1,557,153. The incident date is recorded as December 1, 2022. The data categories are email addresses and partial phone numbers. Since the incident is associated with a third-party email service, the user portfolios or tax data of the main CoinTracker platform should not be presented as part of this record. The record should be considered a leak of contact information indicating that the user may be associated with CoinTracker.\u003C\u002Fp>\n\u003Cp>In this record, a password, passphrase hash, crypto wallet private key, recovery phrase, portfolio balance, transaction history, tax form, payment card, bank account, or official ID is not a verified data class. It is understandable for CoinTracker users to be concerned about these fields due to the crypto context; however, proper record management requires not adding unverified financial and wallet data. The risk arises from targeted fraud due to the combination of contact information with the crypto context.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users at the highest risk are those who use the email address they use for CoinTracker on crypto exchanges, wallet services, accounting tools, or investment communities as well. The reuse of the same address across different crypto services makes it easier for attackers to classify the user as a crypto asset holder or someone tracking taxes. This information can be used in fake tax season warnings, portfolio linking, wallet matching, or account verification messages.\u003C\u002Fp>\n\u003Cp>The second risk group consists of users who are not familiar with the technical details of crypto tax reporting and portfolio tracking. Fake messages such as 'your tax report is ready,' 'your wallet connection is lost,' 'your portfolio is at risk,' or 'your account is awaiting verification' may target these users. Corporate users should also be cautious; employees who register for a crypto tax or portfolio tool using their work email may receive crypto-themed phishing messages in their work inboxes. Even if these messages target individual assets, opening them on work devices can pose corporate risk.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>A user who sees a match in the CoinTracker record should first check the security of their email account. A strong and unique password should be used for the email account, multi-factor authentication should be enabled, and recent sessions should be reviewed. In this incident, the password is not verified; nonetheless, email security is a priority because passwords or wallet information can still be stolen through phishing links. The user should also keep multi-factor authentication active on their CoinTracker and crypto exchange accounts.\u003C\u002Fp>\n\u003Cp>Links in messages themed around CoinTracker, tax reporting, portfolio matching, crypto exchange connections, wallet verification, or airdrops should be carefully examined. If a transaction is to be made, the address of the relevant service should be typed directly into the browser or a trusted bookmark should be used. Private keys, recovery phrases, verification codes, or exchange passwords should not be entered through links in emails. Legitimate crypto services do not request private keys or recovery phrases. Similar requests received by SMS due to partial phone information should also be handled with caution.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Crypto tax and portfolio tracking tools become important even as communication data because they reveal the user's financial interests. In the long term, using a separate email address for crypto services can help separate targeted messages from the main email account. This address should be protected with a strong password, multi-factor authentication, and regular session checks. Unused crypto tools, newsletters, and portfolio links should be closed or at least notification permissions should be reduced.\u003C\u002Fp>\n\u003Cp>For institutions, the security of third-party service providers is as important as the main application. When email delivery systems, customer contact lists, and marketing tools are leaked, targeted attacks may begin even if financial data is not directly affected. The permanent strategy for users is to have a unique password for each crypto service, use multi-factor authentication, check suspicious emails, and develop the habit of not entering private keys into any online forms. Communication data leaks become more manageable with this discipline.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match in this record indicates that the relevant email address is among the accounts associated with the CoinTracker incident. A match does not mean that the user's crypto assets, portfolio balances, tax reports, password, or wallet keys are within the verified scope of this record. The verified scope is limited to the email address and the partial phone field tracked in the breach datasets.\u003C\u002Fp>\n\u003Cp>After securing their email account and CoinTracker account, the user should check the security settings on their crypto exchange and wallet accounts. Any unexpected tax report, portfolio alert, exchange connection, or wallet verification messages should be verified through official channels. Links received via SMS should also be treated with caution due to the possibility that partial phone information could be matched with other data sets. The correct action in this situation is not to panic financially but to strengthen email security and awareness of crypto-themed messages.\u003C\u002Fp>","","CoinTracker Data Breach (1.6 Million Reported Records)","CoinTracker Data Breach. 1.6 Million reported records were reported. Reported data: Email addresses, Partial phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcointracker_io.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":21},"CoinTracker","Cryptocurrency portfolio and tax tracking service","United States"]