Crypto.com May Have Experienced Limited Breach Linked to Scattered Spider, Company Says

ETH

ETH/USDT

$2,021.11
+1.34%
24h Volume

$10,942,985,253.63

24h H/L

$2,046.59 / $1,976.48

Change: $70.11 (3.55%)

Long/Short
77.0%
Long: 77.0%Short: 23.1%
Funding Rate

+0.0033%

Longs pay

Data provided by COINOTAG DATALive data
Ethereum
Ethereum
Daily

$2,018.37

0.19%

Volume (24h): -

Resistance Levels
Resistance 3$2,214.27
Resistance 2$2,124.14
Resistance 1$2,056.24
Price$2,018.37
Support 1$2,012.83
Support 2$1,945.82
Support 3$1,875.80
Pivot (PP):$2,014.64
Trend:Downtrend
RSI (14):32.5
(03:51 AM UTC)
5 min read

Contents

1484 views
0 comments

  • Limited PII exposure, no funds accessed

  • Intrusion traced to social‑engineering/phishing by Scattered Spider members using stolen personal data.

  • Incident contained within hours; criminal prosecutions led to seizures and convictions with estimated related losses reported.

Crypto.com breach confirmed: limited PII exposure, no customer funds at risk. Read timeline, cause, and protections to secure accounts — COINOTAG report.

What happened in the Crypto.com breach linked to Scattered Spider?

Crypto.com breach involved a targeted phishing campaign that led attackers to obtain employee credentials and access internal systems, exposing a small set of personally identifiable information (PII). The incident was contained quickly, reported to regulators, and no customer funds were accessed, according to official statements.

How did attackers from Scattered Spider gain access to Crypto.com?

Investigators found a caller-based social engineering method. A Florida teenager, identified as a “caller” within the Scattered Spider collective, used stolen personal data and impersonation to trick employees into surrendering credentials. Reports indicate tactics included phishing and leveraging leaked data from third‑party sources. Law enforcement later seized crypto assets and pursued prosecutions.


Frequently Asked Questions

How extensive was the data exposure in the Crypto.com breach?

The exposure was limited to a small number of individuals’ PII, according to company and security firm comments. The platform says the incident was contained within hours and regulators were notified through required filings.

Who investigated and commented on the breach?

Blockchain security firm Slowmist and company leadership provided public comments. Media reports mentioning the incident include Bloomberg and COINOTAG as plain‑text sources of early reporting and analysis.

Key Takeaways

  • Containment succeeded: The breach was contained within hours and did not impact customer balances.
  • Attack vector: Social engineering and phishing influenced employee credential disclosure, per investigations.
  • User actions: Change passwords, enable robust MFA, and monitor accounts for suspicious activity.

Conclusion

The Crypto.com incident confirms that targeted social‑engineering campaigns remain an effective threat against centralized platforms. COINOTAG recommends proactive account hygiene and close monitoring of official platform communications. Expect continued regulatory and law enforcement scrutiny as prosecutions proceed and recovery efforts continue.






Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
SC

Sarah Chen

COINOTAG author

View all posts

Comments

Comments