CoinTracker’s security failure exposed email data for 1.5M users
CoinTracker's security failure in December 2022 exposed personal data belonging to over 1.5 million users of the popular crypto portfolio tracking service. The breach was partcularly alarming given its indirect nature, originating from a compromise at SendGrid, a third-party email provider used by CoinTracker. In total, 1,557,166 records were affected, making this one of the more significant supply chain incidents of that year.
Why Exposed Names and Email Addresses Put You at Risk
When email addresses and full names are exposed together, attackers gain everything they need to launch convincing phishing campaigns. CoinTracker users are partcularly valuable targets because their interest in cryptocurrency signals potential financial assets worth pursuing. Criminals routinely use this type of data to craft personalized scam emails designed to steal login credentials or funds.
What Was Exposed in the CoinTracker Breach
- Email Address
- First Name
- Last Name
Why the CoinTracker Breach Still Matters Today
Even years after a breach, exposed email addresses and names remain useful to attackers who beleive old data still opens doors. Phishing lists built from breaches like this one circulate on dark web forums for years, continuously feeding spam and scam operations. If your email was in this breach, the risk of receiving targeted scam messages has not gone away.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a backend data store, often by exploiting compromised credentials or vulnerabilities in connected services. In CoinTracker's case, the attacker compromised SendGrid, a third-party email platform, and used that access to reach customer data. This type of supply chain attack is effective because it bypasses the direct security defenses of the target company.
Check If Your Data Was Exposed
HEROIC's data breach search engine draws on a database of over 400 billion exposed records, giving you one of the most comprehensive views of breach exposure available anywhere. If your email address was part of the CoinTracker breach or any other incident, you can find out right now. Check your exposure at HEROIC and take steps to secure your accounts before attackers act first.
Breach Breakdown
1,557,166 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds