Close Menu
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
    • Mining
  • Stocks
  • Forex
  • Personal Finance
  • World Economy
  • AI in Finance
  • Commodities
  • DeFi
  • Fintech
  • NFTs
  • Learn Finance
Trending
  • Bitcoin Market Not Ready For Expansion Yet — Blockchain Firm
  • 4844 Data Challenge: Insights and Winners
  • Will BTC Remain Above $70K This Weekend?
  • $105 Breakout Or Double-Pair Collapse Ahead?
  • Six weeks until Devcon SEA in Bangkok
  • Investigators Flag Coinbase Page Asking For Seed Phrases, Tool Removed
  • Why The XRP Supply In The Billions Is Not A Problem
  • The Devcon schedule is live!
Facebook X (Twitter) Instagram YouTube
Finance Insider Today
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
    • Mining
  • Stocks
  • Forex
  • Personal Finance
  • World Economy
  • AI in Finance
  • Commodities
  • DeFi
  • Fintech
  • NFTs
  • Learn Finance
Finance Insider Today
Home » Bitcoin
Bitcoin

Bitrefill Discloses Cyberattack, Points To North Korea’s Lazarus Group

FIT Editorial TeamBy FIT Editorial TeamMarch 18, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Crypto e-commerce platform Bitrefill said it was the target of a cyberattack earlier this month that resulted in stolen funds and limited exposure of customer data, with indicators pointing to the North Korean-linked Lazarus Group as a likely perpetrator.

The breach, which began on March 1, originated from a compromised employee laptop, according to the company’s incident report. 

Attackers were able to extract legacy credentials tied to production systems, allowing them to escalate access across Bitrefill’s infrastructure, including segments of its internal database and certain cryptocurrency hot wallets.

Bitrefill said the attackers drained an undisclosed amount of funds from its hot wallets while also exploiting its gift card inventory systems to place suspicious purchases with vendors. The company did not specify the total financial impact but stated it will absorb the losses using operational capital.

The intrusion was first detected through irregular purchasing patterns and anomalies in supplier activity. 

In response, Bitrefill temporarily took its systems offline to contain the breach across its global operations. The company said services, including payments and account access, have since returned to normal levels.

As part of the attack, approximately 18,500 purchase records were accessed. The exposed data includes email addresses, cryptocurrency payment addresses and metadata such as IP addresses. 

Around 1,000 of those records involved encrypted customer names, which are being treated as potentially exposed due to the possibility that attackers accessed encryption keys. Bitrefill said it has notified affected users directly.

Despite the breach, the company emphasized that it stores minimal personal data and does not require mandatory know-your-customer verification for most transactions. Any KYC-related information is handled by external providers and is not stored within Bitrefill’s systems. The firm added there is no evidence that its full database was exfiltrated or that customer data was the primary target.

“Based on our investigation and logs, we don’t have reason to think that customer data was the objective,” the company said, noting that the attackers appeared to conduct limited queries consistent with probing for valuable assets such as cryptocurrency holdings and gift card inventory.

North Korea’s Lazarus Group was involved

Bitrefill cited several indicators linking the attack to the Lazarus Group, including similarities in malware, reused infrastructure such as IP addresses and email accounts, and on-chain transaction patterns. 

The group, often associated with North Korea, has been tied to some of the largest crypto thefts in recent years through its specialized subgroup, Bluenoroff.

Cybersecurity firms including zeroShadow, SEAL911 and RecoverisTeam assisted in the response and investigation, alongside on-chain analysts and law enforcement. The company said it is implementing additional security measures, including expanded monitoring systems and internal controls, to prevent similar incidents.

The attack highlights ongoing concerns around state-sponsored cyber threats in the digital asset sector. 

According to blockchain analytics firm Chainalysis, groups linked to North Korea were responsible for more than $2 billion in crypto thefts in 2025, accounting for a significant share of total illicit activity in the space.

Bitrefill said operations have stabilized following the incident and expressed confidence in its recovery, noting that customer activity and sales volumes have returned to typical levels.



Source link

⚠️ Investment Disclaimer
The content published on Finance Insider Today is for informational and educational purposes only. It does not constitute financial advice, investment advice, or any other form of professional advice. Always conduct your own research and consult a qualified financial advisor before making any investment decisions. Finance Insider Today is not responsible for any financial losses resulting from decisions made based on information published on this website. Past performance is not indicative of future results. Financial markets carry significant risk. Never invest more than you can afford to lose.
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
FIT Editorial Team

Related Posts

Strategy CEO Calls Morgan Stanley ETF A “Monster Bitcoin” Bet

March 21, 2026

White House Reaches Tentative Crypto Agreement: Report

March 21, 2026

Stellar (XLM) Price Prediction 2026 2027 2028

March 21, 2026

Bitcoin Price Holds $70,000 As War-Driven Inflation Fear Rises

March 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

XRP Prints Bullish Divergence On The Weekly Chart, But Is ATHs Still Possible?

January 30, 2026

Trump Memecoin Leaps After the President of the United States Offers Dinner With Top Holders

April 24, 2025

Ethereum Exchange Outflows Signal Supply Is Stepping Back

January 17, 2026

Bitcoin Regains Momentum as US Fed Leaves Rates Unchanged

March 19, 2026

Is It a Legal and Reputable Exchange?

March 9, 2026
CurrencyPrice
UAE Dirham 
UAE Dirham
3.6725
Australian Dollar 
Australian Dollar
1.4232down
Canadian Dollar 
Canadian Dollar
1.3724up
Swiss Franc 
Swiss Franc
0.788down
Renminbi 
Renminbi
6.8847up
Euro 
Euro
0.8628
British Pound 
British Pound
0.7496down
Japanese Yen 
Japanese Yen
159.2377down
Malaysian Ringgit 
Malaysian Ringgit
3.9352down
New Zealand Dollar 
New Zealand Dollar
1.7138up
US Dollar 
US Dollar
1
22 Mar · FX Source: CurrencyRate 
CurrencyRate.Today
Check: 22 Mar 2026 02:45 UTC
Latest change: 22 Mar 2026 02:38 UTC
API: CurrencyRate
Disclaimers. This plugin or website cannot guarantee the accuracy of the exchange rates displayed. You should confirm current rates before making any transactions that could be affected by changes in the exchange rates.
⚡You can install this WP plugin on your website from the WordPress official website: Exchange Rates🚀
Categories
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Forex
  • Mining
  • Personal Finance
  • Stocks
  • World Economy
About us

Finance Insider Today is an independent financial news platform covering global markets, cryptocurrency, economy, fintech, and personal finance. Published daily.

Top Insights

Bitcoin Market Not Ready For Expansion Yet — Blockchain Firm

March 22, 2026

4844 Data Challenge: Insights and Winners

March 22, 2026

Will BTC Remain Above $70K This Weekend?

March 22, 2026
Categories
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Forex
  • Mining
  • Personal Finance
  • Stocks
  • World Economy
X (Twitter) Instagram YouTube
  • About us
  • Contact us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
Copyright © 2026 Financeinsidertoday.com All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.