Full Report
Bitcoin Depot, which operates cryptocurrency ATMs across North America, says information belonging to more than 26,000 people was breached in an incident last year.
Analysis Summary
# Incident Report: Bitcoin Depot Customer Data Breach
## Executive Summary
Cryptocurrency ATM company Bitcoin Depot suffered a significant data breach approximately one year prior to the July 2024 investigation conclusion, resulting in sensitive personal information for over 26,000 customers being exposed. The compromised data included names, phone numbers, addresses, emails, and driver's license numbers. Notification to customers was delayed until recently, pending the conclusion of a law enforcement agency's inquiry.
## Incident Details
- **Discovery Date:** Not explicitly stated, but investigation concluded on July 18, 2024.
- **Incident Date:** Approximately one year prior to July 2024 (estimated mid-2023).
- **Affected Organization:** Bitcoin Depot
- **Sector:** Financial Technology (FinTech) / Cryptocurrency Services
- **Geography:** United States (Atlanta-based operator with ATMs across North America)
## Timeline of Events
### Initial Access
- **Date/Time:** Estimated mid-2023.
- **Vector:** Unspecified cyberattack targeting customer data.
- **Details:** The exact initial access vector is not detailed in the provided context.
### Lateral Movement
- **Details:** Not explicitly detailed, but successful access led to the compromise of a batch of information affecting customer records.
### Data Exfiltration/Impact
- **Details:** Sensitive customer data was stolen, affecting 26,732 individuals. Data included name, phone number, address, email, and driver's license number.
### Detection & Response
- **How it was discovered:** The specific discovery date is not noted, but the company completed its internal investigation by July 18, 2024.
- **Response actions taken:** The company completed an investigation and notified affected customers after an unnamed federal law enforcement agency concluded its inquiry (last month prior to the notification week).
## Attack Methodology
- **Initial Access:** Unknown.
- **Persistence:** Unknown.
- **Privilege Escalation:** Unknown.
- **Defense Evasion:** Unknown.
- **Credential Access:** Unknown.
- **Discovery:** Unknown.
- **Lateral Movement:** Unknown.
- **Collection:** Sensitive PII (Name, Phone, Address, Email, Driver's License Number) was collected.
- **Exfiltration:** Data was exfiltrated in a "batch."
- **Impact:** Disclosure of PII leading to potential identity theft risk.
## Impact Assessment
- **Financial:** Not specified. No identity theft protections were offered, possibly because SSNs were not involved.
- **Data Breach:** Personal Identifiable Information (PII) for 26,732 individuals, including driver's license numbers.
- **Operational:** Business operations appear continued, evidenced by ongoing reporting, but reputational harm is possible given the context of other crypto security incidents.
- **Reputational:** Negative publicity surrounding the data loss, especially given recent high-profile breaches in the crypto sector.
## Indicators of Compromise
- *No actionable Indicators of Compromise (IPs, Domains, Hashes) were provided in the source text.*
## Response Actions
- **Containment measures:** Not detailed.
- **Eradication steps:** Not detailed.
- **Recovery actions:** Completed internal investigation by July 18, 2024, and notified affected parties following law enforcement clearance.
## Lessons Learned
- **Key takeaways:** The necessity of protecting highly sensitive PII, including driver's license numbers, in customer databases.
- **What could have been done better:** Notification timing was significantly delayed (nearly a year post-incident conclusion) pending external agency clearance, leading to delayed consumer protection.
## Recommendations
- **Prevention measures for similar incidents:** Implement segmentation and robust encryption for databases containing driver's license numbers and PII. Enhance breach detection capabilities to shorten the time between compromise and internal investigation conclusion. Review breach notification policies to balance law enforcement cooperation with timely customer awareness.