Meria CEO Warns Fake Binance Calls Target Bitcoin (BTC) Holders After 678,000-Record French Breach

Meria CEO Owen Simonin flags surging fake Binance support calls after France's DGFiP breach exposed data on 678,000 people; no passwords leaked.

(04:35 AM UTC)
4 min read
AI SummaryAI
  • DGFiP breach exposed partial data on 678,000 individuals and businesses between June and August
  • Meria CEO Owen Simonin reported surging fake Binance and Meria support calls targeting crypto users
  • Cybermalveillance recorded a 107% year-over-year rise in data-breach support requests in 2025
  • Fake bank-advisor scam requests in France rose 159% per Cybermalveillance's 2025 report
p9zt4hjs

French Tax Breach Fuels Fake Support Calls

An unauthorized intrusion into France's public-finance system exposed partial data on 678,000 individuals and businesses — and in the days since, a sharp rise in fake customer-support calls impersonating Binance and Meria has followed. Meria founder and CEO Owen Simonin said on Saturday that callers posing as support staff for the two platforms have been telling users their accounts are in danger and instructing them to move assets to a supposedly safe address.

The underlying breach traces to France's Directorate General of Public Finances (DGFiP), which disclosed that intruders viewed and extracted records between June and August. The pulled dataset includes fiscal reference income, the family quotient used in French tax calculations, and withholding rates, alongside business names, company identification numbers, and real-estate addresses and floor areas. DGFiP stressed that the official tax site and taxpayer accounts themselves were never compromised and that no usernames or passwords leaked; investigators are still confirming the precise categories and volume of what was taken.

What the extraction demonstrably does not contain is crypto-holding or exchange-usage data — no such link has been established. Simonin's assertion is narrower: leaked datasets from private companies and public agencies are combining to the point where a caller can infer whether a given person holds digital assets and on which platform. Which leaked file actually fed the fraudulent calls, and the scale of resulting losses, both remain unconfirmed.

The distinction matters for blockchain node operators and exchange users alike, because a confirmed exchange-link would convert indiscriminate phishing into genuine targeting of Bitcoin (BTC) and other major-asset holders. Until DGFiP publishes its extraction inventory, the direct causal claim stays unproven — the surge in calls is real, but the data source behind it is not yet verified.

Simonin Sounds the Alarm Publicly

The Meria chief's public warning laid out how the leak interlock works: “We are going through a phase where data breaches keep accumulating across private companies and public bodies — all of these leaks interlock, and it is precisely through this that crypto holders and their platforms get identified,” he stated, tying the call surge to breaches that have affected millions of French citizens.

The scam playbook is consistent across cases: the caller warns that funds are at risk and presses for an immediate transfer to “secure” them, exploiting urgency. “If you panic and comply, your money goes to their address,” Simonin cautioned. He added that a legitimate service provider never calls unprompted — unless the user initiated contact about a specific issue — and never requests a transfer or personal information.

He expects artificial intelligence to amplify the phenomenon, giving attackers more computing power and the ability to automate convincing voice fraud — a trajectory with implications for chip supply chains like Taiwan Semiconductor (TSM), which builds the accelerators behind such systems. France's broader crypto-crime trend is also turning physical, with holders increasingly targeted in wrench attacks.

Binance's own advisory reinforces the defensive checklist: caller ID can be spoofed to display what looks like the genuine support number, and the exchange states it never calls users unannounced to discuss account security or authentication. Users should hang up and open the official application or website directly — never share passwords, recovery phrases, or verification codes inbound. France's cyber-support agency Cybermalveillance.gouv.fr reported in its 2025 activity report that impersonation of Binance, Ledger, and Coinhouse is rising, with data-breach-related requests at 6.6% of individual cases — up 107% year over year — and fake bank-advisor scam requests up 159%. Readers tracking the market in real time can follow live spot and futures prices on Bybit.

AI Automation Set to Scale the Threat

Both threads converge on one arc: aggregated leaks are turning mass phishing into targeted hunting of crypto holders, and automation will raise the volume. The load-bearing primary records here are DGFiP's own disclosure — it confirms the June–August intrusion and the 678,000 figure while stating no passwords were taken — and Simonin's public post detailing the fraud pattern. The episode also underscores how centralized identity troves, from tax records to the biometric files collected by projects like Worldcoin, function as honeypots; COINOTAG's view is that France's crypto-security surface now spans voice impersonation alongside threats from cryptojacking malware to violent wrench attacks. Until the extraction inventory is published, treat every unprompted call as hostile.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.