{"id":246255,"date":"2025-09-22T12:08:21","date_gmt":"2025-09-22T12:08:21","guid":{"rendered":"https:\/\/www.europesays.com\/us\/246255\/"},"modified":"2025-09-22T12:08:21","modified_gmt":"2025-09-22T12:08:21","slug":"crypto-com-team-covered-up-a-breach-scattered-spider-breach-revealed","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/246255\/","title":{"rendered":"Crypto.com team &#8216;covered up a breach&#8217; &#8211; Scattered Spider breach, revealed!"},"content":{"rendered":"<p>\t\t\t\t\t\t\t\tKey Takeaways<br \/>\nWere Crypto.com customer funds affected?<\/p>\n<p>No, Crypto.com confirmed that no customer funds were accessed or at risk. Only a very small number of users\u2019 partial personal information was affected.<\/p>\n<p>Did Crypto.com disclose the breach publicly?<\/p>\n<p>No, the company did not publicly notify the impacted users, which drew criticism from blockchain investigator ZachXBT.<\/p>\n<p>Crypto.com reportedly suffered a previously undisclosed data breach linked to the Scattered Spider hacking group, raising concerns over its security posture.<\/p>\n<p><strong>Details of the attack<\/strong><\/p>\n<p><a href=\"https:\/\/www.bloomberg.com\/news\/features\/2025-09-19\/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">According<\/a> to a Bloomberg investigation, the attack involved teenage hackers, including 18-year-old Noah Urban from Florida, who specialized in phishing employees at telecom, tech, and cryptocurrency firms. <\/p>\n<p>Urban and his collaborators accessed sensitive user information. The group previously targeted MGM Resorts and other corporations.<\/p>\n<p>Crypto.com acknowledged that the breach impacted \u201ca very small number of individuals\u201d but emphasized that no customer funds were compromised.<\/p>\n<p><strong>Crypto.com\u2019s response<\/strong><\/p>\n<p> Despite this, the company did not notify the affected users publicly.<\/p>\n<p>Remarking on the same, Crypto.com CEO, Kris Marszalek, <a href=\"https:\/\/x.com\/kris\/status\/1969917615276793990\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">noted<\/a>,\u00a0<\/p>\n<blockquote>\n<p>\u201cAny suggestion that we did not report or disclose a security incident is completely unfounded \u2013 as we reported in a NMLS Notice of Data Security incident filing and in additional reports with the relevant jurisdictional regulators, we detected a phishing campaign that targeted one of our employees in 2023.\u201d<\/p>\n<\/blockquote>\n<p>Marszalek stated that the incident was contained within hours, with no customer funds ever at risk, and only a very limited number of users\u2019 partial personal information was affected. <\/p>\n<p>He even emphasized the company\u2019s \u201csecurity-first\u201d culture.<\/p>\n<p><strong>What does ZachXBT have to say about this breach?<\/strong><\/p>\n<p>However, blockchain investigator ZachXBT <a href=\"https:\/\/x.com\/zachxbt\/status\/1969712380939833447\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">took<\/a> to X to call out Crypto.com for not disclosing the data breach. He said,<\/p>\n<blockquote>\n<p>\u201cYour team covered up a breach that impacted the personal information of your users.\u201d<\/p>\n<\/blockquote>\n<p>He <a href=\"https:\/\/x.com\/zachxbt\/status\/1969718961567940951\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">added<\/a>,\u00a0<\/p>\n<blockquote>\n<p>\u201cThey\u2019ve been breached several times.\u201d<\/p>\n<\/blockquote>\n<p>That being said, the Crypto.com breach was part of a larger criminal campaign orchestrated by the Scattered Spider group, which had evolved from simple SIM-swapping to sophisticated corporate infiltration.<\/p>\n<p> Florida native Noah Urban, then a teenager, acted as a \u201ccaller\u201d inside the group, persuading employees to hand over credentials that unlocked internal systems.<\/p>\n<p><strong>Broader criminal campaign<\/strong><\/p>\n<p>The attack happened before March 2023. Urban was arrested nine months later, in January 2024, and charged with hacking 13 companies.<\/p>\n<p>Authorities said the group also misused United Parcel Service data.<\/p>\n<p>Following indictments of Urban and four accomplices, he pled guilty to wire fraud and aggravated identity theft.<\/p>\n<p>It resulted in the seizure of $4.8 million in crypto, $13 million in restitution, and a 10-year prison sentence with additional supervised release.<\/p>\n<p>All these disclosures coincided with CEO Marszalek\u2019s <a href=\"https:\/\/ambcrypto.com\/crypto-com-ceo-predicts-strong-q4-on-hopes-of-fed-rate-cuts\/amp\/\" target=\"_blank\" rel=\"noopener nofollow\" data-wpel-link=\"internal\">predictions<\/a> of a strong fourth-quarter performance and a <a href=\"https:\/\/ambcrypto.com\/trump-media-crypto-com-unveil-6-4b-cronos-treasury-strategy-details\/amp\/\" target=\"_blank\" rel=\"noopener nofollow\" data-wpel-link=\"internal\">partnership<\/a> with Yorkville Acquisition Corp. and Trump Media to form Trump Media Group CRO Strategy, Inc., a digital asset treasury focused on acquiring Cronos (CRO). <\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\tPrevious: <a href=\"https:\/\/ambcrypto.com\/dogecoin-why-this-cycle-can-have-doges-most-sustainable-rally-yet\/\" rel=\"next nofollow noopener\" data-wpel-link=\"internal\" target=\"_blank\">Dogecoin: Why this cycle can have DOGE\u2019s most sustainable rally yet<\/a>\t\t\t\t\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\tNext: <a href=\"https:\/\/ambcrypto.com\/solana-emerges-as-the-go-to-network-for-wrapped-bitcoin-impact-on-sol\/\" rel=\"prev nofollow noopener\" data-wpel-link=\"internal\" target=\"_blank\">Solana emerges as the go-to network for Wrapped Bitcoin: Impact on SOL?<\/a>\t\t\t\t\t\t\t\t\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"Key Takeaways Were Crypto.com customer funds affected? No, Crypto.com confirmed that no customer funds were accessed or at&hellip;\n","protected":false},"author":3,"featured_media":246256,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[3244,64,67,132,68],"class_list":{"0":"post-246255","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"tag-ambcrypto","9":"tag-business","10":"tag-united-states","11":"tag-unitedstates","12":"tag-us"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/115247874390050452","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/246255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=246255"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/246255\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/246256"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=246255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=246255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=246255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}