[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foydqm8q6aqcr":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":19,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":8,"seoDescription":30,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"6a720f18e5722ee73c294b48","Kroll2023","Kroll 2023 Data Breach","kroll-2023","kroll.com","2023-08-19T00:00:00.000Z","2026-08-04T16:11:04.604Z","Kroll security-incident statement preserved by independent reporting","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkroll-data-breach-exposes-info-of-ftx-blockfi-genesis-creditors\u002F",[14,16,17,18],"https:\u002F\u002Fwww.kroll.com\u002Fen\u002Fabout-us\u002Fnews\u002Fsecurity-incident","https:\u002F\u002Fkrebsonsecurity.com\u002F2023\u002F08\u002Fkroll-employee-sim-swapped-for-crypto-investor-data\u002F","https:\u002F\u002Fwww.cnbc.com\u002F2023\u002F08\u002F25\u002Fftx-blockfi-genesis-customer-data-compromised-in-kroll-hack.html",null,"unknown","people","Unknown",[24,25,26,27,28],"Email addresses","Names","Physical addresses","Contact information","Bankruptcy claim information","\u003Cp>\u003Cstrong>The 2023 Kroll data breach\u003C\u002Fstrong> was an account-compromise incident that exposed some claimant files maintained for the FTX, BlockFi and Genesis bankruptcy proceedings. Kroll said it was informed on August 19, 2023 that an employee's phone number had been targeted in a SIM-swapping attack.\u003C\u002Fp>\u003Cp>The incident was limited to specific accounts and files used in Kroll's restructuring work. FTX and BlockFi said their own systems were not directly breached and that customer funds and account passwords were not affected.\u003C\u002Fp>\u003Ch2>How did the Kroll data breach happen?\u003C\u002Fh2>\u003Cp>According to Kroll's statement, an attacker caused a T-Mobile phone number belonging to an employee to be transferred to another SIM without authorization. Control of the number was then used to access the employee's account.\u003C\u002Fp>\u003Cp>The attacker subsequently accessed files containing personal information about some claimants in the BlockFi, FTX and Genesis bankruptcy matters. The published findings do not indicate that the companies' trading platforms were compromised.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>Independent reporting identifies names, postal addresses, contact details and debtor-claim information among the data held in the accessed files. The exact categories may vary by person and bankruptcy matter.\u003C\u002Fp>\u003Cp>Kroll and the affected companies said account passwords and customer funds were not involved. That distinction does not remove the risk of convincing messages tailored to individual claimants.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>Kroll has not publicly disclosed a unique affected-person total. Notifications were sent to people identified as affected; the overall customer or claimant populations of FTX, BlockFi and Genesis are not used as a breach count.\u003C\u002Fp>\u003Ch2>What risks can this incident create?\u003C\u002Fh2>\u003Cp>Accurate bankruptcy-claim details can make fake withdrawal notices or promised claim payments appear credible. Phishing messages impersonating FTX were reported after the incident.\u003C\u002Fp>\u003Cp>A message containing a correct name, address or claim detail does not prove that the sender is authorized. Unexpected requests for transfers, wallet connections or identity documents should be treated cautiously.\u003C\u002Fp>\u003Ch2>How did Kroll respond?\u003C\u002Fh2>\u003Cp>Kroll said it secured the three affected accounts, contained the incident and notified affected individuals. FTX and BlockFi also warned customers through their own communication channels.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>A bankruptcy-related notice should be verified through the official Kroll restructuring portal for the relevant case rather than through a link in an email. Unexpected requests for passwords, verification codes, wallet keys or payment should not be answered.\u003C\u002Fp>\u003Cp>Claimants can monitor account activity, use a unique password for every service and prefer app- or hardware-key-based multi-factor authentication over SMS when available.\u003C\u002Fp>","","Kroll's 2023 incident exposed claimant files from the FTX, BlockFi and Genesis cases. Review the confirmed scope, risks and practical safeguards.","\u002Fuploads\u002Flogo\u002Fkroll-official.svg",false,{"name":35,"sector":36,"country":37,"website":38,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":19},"Kroll","Professional Services","United States","https:\u002F\u002Fwww.kroll.com\u002Fen"]