{"id":874888,"date":"2025-09-22T21:13:39","date_gmt":"2025-09-23T02:13:39","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2025\/09\/22\/crypto-com-team-covered-up-a-breach-scattered-spider-breach-revealed\/"},"modified":"2025-09-22T21:13:39","modified_gmt":"2025-09-23T02:13:39","slug":"crypto-com-team-covered-up-a-breach-scattered-spider-breach-revealed","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2025\/09\/22\/crypto-com-team-covered-up-a-breach-scattered-spider-breach-revealed\/","title":{"rendered":"Crypto.com team \u2018covered up a breach\u2019 \u2013 Scattered Spider breach, revealed!"},"content":{"rendered":"<div id=\"single-post-wrapper\">\n<p><img width=\"1200\" height=\"675\" src=\"https:\/\/ambcrypto.com\/wp-content\/uploads\/2025\/09\/Crypto.com-Suffered-an-Unreported-Data-Breach-1200x675.webp\" alt=\"Crypto.com 'team covered up a breach' - Scattered Spider breach, revealed!\" decoding=\"async\" fetchpriority=\"high\"  >\n\t\t\t\t\t\t<\/p>\n<div>\n<div>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" data-del=\"avatar\" alt=\"Avatar\" src=\"https:\/\/ambcrypto.com\/wp-content\/uploads\/2022\/08\/IMG_20220817_125232_826-scaled-e1661058408776-80x80.jpg\" height=\"48\" width=\"48\"><\/p>\n<p>Journalist<\/p>\n<\/p><\/div>\n<div>\n<p><span>Posted: <time itemprop=\"datePublished\" datetime=\"2025-09-22\">September 22, 2025<\/time><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><\/p>\n<p><meta itemprop=\"dateModified\" content=\"2025-09-22 4:38 pm\"><\/p><\/div>\n<\/p><\/div>\n<div>\n<h2>Key Takeaways<\/h2>\n<h3><em>Were Crypto.com customer funds affected?<\/em><\/h3>\n<p>No, Crypto.com confirmed that no customer funds were accessed or at risk. Only a very small number of users\u2019 partial personal information was affected.<\/p>\n<h3><em>Did Crypto.com disclose the breach publicly?<\/em><\/h3>\n<p>No, the company did not publicly notify the impacted users, which drew criticism from blockchain investigator ZachXBT.<\/p>\n<hr>\n<p>Crypto.com reportedly suffered a previously undisclosed data breach linked to the Scattered Spider hacking group, raising concerns over its security posture.<\/p>\n<h2><strong>Details of the attack<\/strong><\/h2>\n<p><span><a href=\"https:\/\/www.bloomberg.com\/news\/features\/2025-09-19\/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">According<\/a> to a Bloomberg investigation, the attack involved teenage hackers, including 18-year-old Noah Urban from Florida, who specialized in phishing employees at telecom, tech, and cryptocurrency firms. <\/span><\/p>\n<p>Urban and his collaborators accessed sensitive user information. The group previously targeted MGM Resorts and other corporations.<\/p>\n<p><span>Crypto.com acknowledged that the breach impacted \u201ca very small number of individuals\u201d but emphasized that no customer funds were compromised.<\/span><\/p>\n<h2><strong>Crypto.com\u2019s response<\/strong><\/h2>\n<p><span> Despite this, the company did not notify the affected users publicly.<\/span><\/p>\n<p><span>Remarking on the same, <\/span><span>Crypto.com<\/span><span> CEO, Kris Marszalek, <a href=\"https:\/\/x.com\/kris\/status\/1969917615276793990\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">noted<\/a>,\u00a0<\/span><\/p>\n<blockquote>\n<p><span>\u201cAny suggestion that we did not report or disclose a security incident is completely unfounded \u2013 as we reported in a NMLS Notice of Data Security incident filing and in additional reports with the relevant jurisdictional regulators, we detected a phishing campaign that targeted one of our employees in 2023.\u201d<\/span><\/p>\n<\/blockquote>\n<p><span>Marszalek stated that the incident was contained within hours, with no customer funds ever at risk, and only a very limited number of users\u2019 partial personal information was affected. <\/span><\/p>\n<p><span>He even emphasized the company\u2019s \u201csecurity-first\u201d culture.<\/span><\/p>\n<h2><strong>What does ZachXBT have to say about this breach?<\/strong><\/h2>\n<p><span>However, blockchain investigator ZachXBT <a href=\"https:\/\/x.com\/zachxbt\/status\/1969712380939833447\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">took<\/a> to X to call out Crypto.com for not disclosing the data breach. He said,<\/span><\/p>\n<blockquote>\n<p><span>\u201cYour team covered up a breach that impacted the personal information of your users.\u201d<\/span><\/p>\n<\/blockquote>\n<p><span>He <a href=\"https:\/\/x.com\/zachxbt\/status\/1969718961567940951\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\">added<\/a>,\u00a0<\/span><\/p>\n<blockquote>\n<p><span>\u201cThey\u2019ve been breached several times.\u201d<\/span><\/p>\n<\/blockquote>\n<p><span>That being said, the Crypto.com breach was part of a larger criminal campaign orchestrated by the Scattered Spider group, which had evolved from simple SIM-swapping to sophisticated corporate infiltration.<\/span><\/p>\n<p><span> Florida native Noah Urban, then a teenager, acted as a \u201ccaller\u201d inside the group, persuading employees to hand over credentials that unlocked internal systems.<\/span><\/p>\n<h2><strong>Broader criminal campaign<\/strong><\/h2>\n<p>The attack happened before March 2023. Urban was arrested nine months later, in January 2024, and charged with hacking 13 companies.<\/p>\n<p>Authorities said the group also misused United Parcel Service data.<\/p>\n<p>Following indictments of Urban and four accomplices, he pled guilty to wire fraud and aggravated identity theft.<\/p>\n<p>It resulted in the seizure of $4.8 million in crypto, $13 million in restitution, and a 10-year prison sentence with additional supervised release.<\/p>\n<p><span>All these disclosures coincided with CEO Marszalek\u2019s <a href=\"https:\/\/ambcrypto.com\/crypto-com-ceo-predicts-strong-q4-on-hopes-of-fed-rate-cuts\/amp\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\">predictions<\/a> of a strong fourth-quarter performance and a <a href=\"https:\/\/ambcrypto.com\/trump-media-crypto-com-unveil-6-4b-cronos-treasury-strategy-details\/amp\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\">partnership<\/a> with Yorkville Acquisition Corp. and Trump Media to form Trump Media Group CRO Strategy, Inc., a digital asset treasury focused on acquiring Cronos (CRO). <\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" data-del=\"avatar\" alt=\"Avatar\" src=\"https:\/\/ambcrypto.com\/wp-content\/uploads\/2022\/08\/IMG_20220817_125232_826-scaled-e1661058408776-150x150.jpg\" height=\"140\" width=\"140\" data-old-src=\"data:image\/svg+xml,%3Csvg%20xmlns='http:\/\/www.w3.org\/2000\/svg'%20viewBox='0%200%20140%20140'%3E%3C\/svg%3E\" data-lazy-src=\"https:\/\/ambcrypto.com\/wp-content\/uploads\/2022\/08\/IMG_20220817_125232_826-scaled-e1661058408776-150x150.jpg\"><\/p>\n<ul>\n<li><a href=\"https:\/\/twitter.com\/IshikaAMBcrypto\" alt=\"Twitter\" target=\"_blank\" aria-label=\"Author Twitter\" data-wpel-link=\"external\" rel=\"nofollow external noopener noreferrer\"><\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/ishika-kumari-\/\" alt=\"LinkedIn\" target=\"_blank\" aria-label=\"Author LinkedIn\" data-wpel-link=\"external\" rel=\"nofollow external noopener noreferrer\"><\/a><\/li>\n<\/ul><\/div>\n<div>\n<p>Ishika Kumari is a Crypto Analyst and Content Strategist at AMBCrypto, specializing in the analysis of cryptocurrency regulations, market trends, and the socio-political impact of blockchain technology.<\/p>\n<p>Her expertise is grounded in her academic background as a graduate of Political Science from the renowned University of Delhi. This discipline has equipped her with a sophisticated framework for analyzing complex governance models, international regulatory landscapes, and the economic principles that underpin decentralized systems.<\/p>\n<p>At AMBCrypto, Ishika applies this unique analytical lens to her work. She excels at breaking down intricate subjects\u2014from the technicalities of new protocols to the nuances of global crypto legislation\u2014into clear, accessible, and insightful content. Her primary mission is to bridge the gap between the complexity of the digital asset industry and the everyday reader, ensuring that AMBCrypto&#8217;s audience is not just informed, but truly understands the forces shaping the future of finance.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p><a href=\"https:\/\/ambcrypto.com\/crypto-com-team-covered-up-a-breach-scattered-spider-breach-revealed\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Ishika Kumari<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Journalist Posted: September 22, 2025 Key Takeaways Were Crypto.com customer funds affected? No, Crypto.com confirmed that no customer funds were accessed or at risk. Only a very small number of users\u2019 partial personal information was affected. Did Crypto.com disclose the breach publicly? No, the company did not publicly notify the impacted users, which drew criticism<\/p>\n","protected":false},"author":1,"featured_media":874889,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23652,22791],"tags":[],"class_list":{"0":"post-874888","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-covered","8":"category-crypto"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/874888","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=874888"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/874888\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/874889"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=874888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=874888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=874888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}