IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Bitcoin scam exposes the personal details of 250,000 people

The UK and Australia represent approximately 93% of users hit by the crypto-scam

cryptocurrency

A cryptocurrency investment scam has exposed the personal details of hundreds of thousands of people around the world. 

Group-IB, a Singapore-based intelligence company, uncovered the stolen personal records of 248,926 people from the UK, Australia, South Africa, Spain, Singapore, the US, Malaysia and other countries. 

The United Kingdom and Australia represent approximately 93% of all affected users. 

It’s not known exactly where or how the leak originated, but Group-IB has discovered that it’s being used in a multi-stage cryptocurrency investment scam that comes at the victims in three phases. 

To begin with, the target receives a text message that is masked as a local media outlet. The link bears a headline boasting that a celebrity endorses a new get-rich-now investment, and each text message also contains a short, unique link.

When the target clicks the link, they are taken to a fake news website that displays a long, personalized URL that includes the target’s name, phone number, and sometimes, email address. 

The fake news site shows made-up content about a particular celebrity who made a fortune with a new cryptocurrency investment platform. Celebrities whose names and images were stolen for this scam include Bryan Wong, Travers ’Candyman’ Beynon, Gina Rinehart, Andrew Forrest, Chris Brown and others. 

The use of celebrity names and images to promote scams is nothing new. Earlier this month Elon Musk’s name was used in a Bitcoin giveaway scam

If the target clicks on that second link, they are taken to a fake cryptocurrency investment platform site where their personal information is already preloaded into the signup form. If they join, they are then asked to add to their account using cryptocurrency. 

Group-IB detected six active domains that offer the same Bitcoin investment platform but operate under different names including Crypto Cash, Bitcoin Supreme, Bitcoin Rejoin and Banking on Blockchain. 

Group-IB CEO, Ilya Sachkov, states in the company’s report on the scam: “The bad guys got smarter in a bid to increase the success rate of their fraudulent operations. Using personal data allows them to carry out targeted attacks and make a victim’s journey easier and smoother, which levels up the overall effectiveness of the scheme.”

The firm has shared its findings with the appropriate law enforcement groups in the affected countries for further investigation. 

Featured Resources

Defending against malware attacks starts here

The ultimate guide to building your malware defence strategy

Free Download

Datto SMB cyber security for MSPs report

A world of opportunity for MSPs

Free Download

The essential guide to preventing ransomware attacks

Vital tips and guidelines to protect your business using ZTNA and SSE

Free Download

Medium businesses: Fuelling the UK’s economic engine

A Connected Thinking report

Free Download

Recommended

Surging inflation is driving people to cryptocurrencies
cryptocurrencies

Surging inflation is driving people to cryptocurrencies

11 Aug 2022
What is cryptocurrency mining?
cryptocurrencies

What is cryptocurrency mining?

27 May 2022

Most Popular

The big PSTN switch off: What’s happening between now and 2025?
Sponsored

The big PSTN switch off: What’s happening between now and 2025?

13 Mar 2023
Why the floppy disk may never die
Server & storage

Why the floppy disk may never die

27 Mar 2023
UK snares "several thousand" potential hackers in DDoS-for-hire honeypot
cyber crime

UK snares "several thousand" potential hackers in DDoS-for-hire honeypot

27 Mar 2023