Bits of Gold, Israel’s largest regulated cryptocurrency broker, disclosed a data breach after attackers gained unauthorized access through a third-party vendor system tied to a broader software supply-chain incident. The Tel Aviv-based firm said the compromise may have affected about 200,000 customers and exposed personal and financial information including names, national ID numbers, email addresses, contact details, IP addresses, bank account numbers, and public cryptocurrency wallet addresses.
The company said there is no indication it was specifically targeted and reported that passwords, private keys, scanned IDs, full payment card numbers, and card security codes were not exposed. Bits of Gold isolated the affected system, notified regulators, and brought in a specialized incident response firm, while the identity of the compromised vendor and the full scope of affected customers remain under investigation; the company also said it has not yet found evidence of malicious use of the stolen data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Bits of Gold publicly reported the incident on Sunday, describing it as part of a broader attack on a software provider that may have affected hundreds of businesses worldwide. Separate reporting said the breach affected roughly 200,000 customers, though Bits of Gold had not confirmed that figure.
On Aug. 16, Bits of Gold notified customers that a breach in a third-party vendor system may have exposed personal and financial data, including names, national ID numbers, contact details, IP addresses, bank account numbers, and public wallet addresses. The company said passwords, private keys, scanned IDs, and full payment card data were not affected.
After detecting the intrusion, Bits of Gold said it disconnected the compromised third-party system from its data sources, alerted regulators, and engaged a specialized cyber incident response firm to investigate. The company also said it found no evidence at that stage of malicious use of the exposed data.
Bits of Gold said it discovered unauthorized access in a third-party system used for customer support and data analysis. The company said the breach originated from a software vendor rather than a direct compromise of its own network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.