BlockFi said an attacker got hold of usersâ data by compromising an employeeâs phone and taking control of the personâs phone number through a SIM swap attack.
The New York-based crypto lending platform announced in a memo to users on Tuesday that a hacker â whose identity remains unknown â gained access to some of its retail marketing systems for just over an hour early on May 14.
âOn May 14, there was a data incident at BlockFi that exposed certain client account information for a brief period of time. While no information was accessed that would enable the intruder to access your account or your funds, we believe it is in the interest of transparency to share the following details with you, and all of our other clients who were potentially affected,â reads the memo, which was shared with CoinDesk.
BlockFi said the hacker accessed confidential data, such as names, dates of birth, postal addresses and activity histories. Other sensitive account information including bank account details, social security and tax identification numbers, passport and driverâs license numbers and photo scans, were not affected in the data breach, the company said.
User funds were also not affected.
See also: CoinDesk Explains SIM Jacking
In an incident report, also published Tuesday, BlockFi said the hacker had accessed through an employeeâs phone. By tricking the mobile phone operator into activating the employeeâs phone number on another device, the hacker was able to access some parts of the companyâs internal systems.
âA BlockFi employeeâs phone number was breached and utilized by an unauthorized third party to access a portion of BlockFiâs encrypted back-office system,â the incident report reads. âThe unauthorized third party was able to access BlockFi client information typically used by BlockFi for retail marketing purposes throughout the duration of this incident.â
The report adds the hacker tried, unsuccessfully, to make withdrawals of user funds, before BlockFi was finally able to remove them from the internal system.
See also: Crypto Execâs $1.8M SIM-Swap Lawsuit Has âCritical Holes,â Says AT&T
In a statement, a BlockFi spokesperson said: âA sole intruder gained minimal access for a short period of time to select internal marketing systems. The BlockFi team immediately mitigated the impact of the breach through a number of standing policies and safeguards in place to protect client assets and data.â
âThe issue has since been resolved and BlockFiâs products and services are fully operational and secure,â the spokesperson added.
The spokesperson did not specify which mobile network the employee used.