tradingkey.logo

Kroll hit with class action over FTX data breach

Cryptopolitan2025年8月22日 09:22

A class action lawsuit has been filed on financial firm and FTX victim reimbursement handlers Kroll. Creditors claimed that their personal information was leaked in a 2023 data breach, exposing them to phishing attacks. 

The lawsuit was submitted on Tuesday by Hall Attorneys representing FTX customer Jacob Repko and other affected parties, in a US court for the Western District of Austin, Texas. 

According to court documents, the breach occurred on or about August 19, 2023, when an unauthorized third party got a hold of a mobile phone number belonging to a Kroll employee. 

After obtaining the contact, the hackers used it to infiltrate Kroll’s cloud-based systems and obtain files containing sensitive creditor data including customer names, home addresses, email addresses, and balances in the fallen crypto trading platform’s accounts.

Kroll issues notice for data breach

Kroll confirmed the breach in a notice to creditors, insisting that no FTX passwords or digital assets were compromised. 

“The attacker might use this information in a further scam, for example, by sending phishing emails to trick you into providing sensitive personal information,” Kroll said at the time. 

The firm added that other accounts and systems were not impacted and that FTX assets were unaffected.

However, Hall attorneys claim the breach has exposed creditors to scam emails and direct financial losses. Repko, the lead plaintiff, told the court that he lost 1.9 ETH in July 2025 after a phishing attack diverted funds he was attempting to transfer into his digital wallet.

The complaint also mentioned there were operational problems with the FTX Customer Claims Portal. According to Repko, his Know Your Customer (KYC) status repeatedly toggled between “Verified” and “On Hold/Unverified,” preventing him from uploading the necessary tax forms required for distributions. 

Per the plaintiff, even after making multiple attempts and writing dozens of support emails, he was unable to resolve the issue.

“Because the FTX Portal gates tax-form upload behind ‘KYC Verified,’ Plaintiff cannot complete the final prerequisites; under the confirmed plan and trust communications, claims may be expunged or distributions forfeited if tax forms are not timely uploaded,” the filing read.

Daily phishing complaints from creditors

According to a Thursday X post made by FTX creditor and activist Sunil Kavuri, creditors have been receiving scam emails nearly every day. Kavuri shared one message he received with his name embedded in the message, alongside several phishing attempts between August 14 and as recent as last Sunday.

Other users joined Kavuri with incidents of their own phishing attempt experiences, with one responding that they had also received similar fraudulent messages. 

The class action demands Kroll to make systemic changes in how it handles creditor’s information, such as including multi-channel notices through both email and physical mail, mailed status-change letters with mandatory cure windows, and the option for creditors to upload tax forms manually without KYC gating.

This is a servicing case, after a known security incident and impersonation wave, you can’t run deadlines on email-only and offer no mailed confirmations or manual fallback,” wrote Nicholas Hall, lead counsel for the plaintiffs, in a press statement.

Hall also said that eligible participants could receive monetary compensation depending on the court’s ruling, and the case could force operational changes at Kroll. His firm, Hall Attorneys, also operates the beleaguered exchange’s claims website and provides assistance to creditors managing their claims.

Get $50 free to trade crypto when you sign up to Bybit now

免责声明:本网站提供的信息仅供教育和参考之用,不应视为财务或投资建议。

相关文章

Tradingkey
tradingkey.logo
tradingkey.logo
日内数据由路孚特(Refinitiv)提供,并受使用条款约束。历史及当前收盘数据均由路孚特提供。所有报价均以当地交易所时间为准。美股报价的实时最后成交数据仅反映通过纳斯达克报告的交易。日内数据延迟至少15分钟或遵循交易所要求。
* 参考、分析和交易策略由第三方提供商Trading Central提供,观点基于分析师的独立评估和判断,未考虑投资者的投资目标和财务状况。
风险提示:我们的网站和移动应用程序仅提供关于某些投资产品的一般信息。Finsights 不提供财务建议或对任何投资产品的推荐,且提供此类信息不应被解释为 Finsights 提供财务建议或推荐。
投资产品存在重大投资风险,包括可能损失投资的本金,且可能并不适合所有人。投资产品的过去表现并不代表其未来表现。
Finsights 可能允许第三方广告商或关联公司在我们的网站或移动应用程序的任何部分放置或投放广告,并可能根据您与广告的互动情况获得报酬。
© 版权所有: FINSIGHTS MEDIA PTE. LTD. 版权所有
KeyAI