Today, cryptocurrency lending platform Celsius Network officially confirmed a data breach resulting from a phishing attack that affected part of its customer base.
Celsius CEO Alex Mashinsky said that a third-party server used by the company for email communications had been compromised. The attackers gained access to part of the customer list and sent them phishing emails.
“An unauthorized person was able to access a backup mailing system associated with a portion of customer email addresses. As a result, fraudulent emails were sent from this system, some of which were received by Celsius customers,” the company said in a statement.
After obtaining the database, the attackers sent emails with a link to a website styled to resemble Celsius’ corporate identity — celsiuswallet[.]network (currently unavailable). Users were asked to create a so-called Celsius Web Wallet and enter their seed phrase.
According to the company, the scammers’ goal was to convince users of the authenticity of the email and website, and then take control of customers’ cryptocurrency by requesting the secret data of their personal wallets.
The phishing emails advertised a non-existent service called Celsius Web Wallet and promised a reward of $500 in CEL tokens for creating a wallet using a “promo code.” To “connect” the wallet, victims were asked to enter a seed phrase, which allowed the attackers to import the wallet and withdraw funds.
According to VirusTotal, the domain celsiuswallet[.]network was registered with the Swedish registrar Njalla, which had previously been used by well-known hacker groups, including Fancy Bear and Cozy Bear.