Gemini discloses breach at banking partner exposing customer account details
- Organization
- Gemini
- Exploit
- Third-Party Data Breach
- Industry
- Cryptocurrency Exchange
Cryptocurrency exchange Gemini disclosed in 2024 that customer banking information had been exposed through a compromise at a third party rather than at the exchange itself. The affected supplier provided Automated Clearing House services that Gemini used to move funds between customer accounts and banks.
According to the notification, an unauthorized party had access to the vendor's systems between June 3 and June 7, 2024. Infosecurity Magazine reported that the actor reached an internal collaboration tool on the banking partner's system, which may have led to the disclosure of transactional data. Gemini said the exposed fields were limited to customer names, bank account numbers and routing numbers, and that dates of birth, physical addresses, Social Security numbers, email addresses, phone numbers, usernames and passwords were not held on the vendor's systems and were not compromised.
Gemini began notifying affected individuals on June 26, 2024, and filed a sample notification letter with the California Attorney General's office in late July, which is how the incident became widely known. Infosecurity Magazine reported that roughly 15,000 customers were affected. The notification letter itself did not give a total.
Gemini said the banking partner engaged outside forensic specialists, contained the incident and notified law enforcement, and that the investigation was continuing as of the reporting date. The exchange did not name the vendor. Gemini had been affected by an earlier supply chain incident in 2022 that exposed customer email addresses and partial phone numbers.