CSIDB logo
Incident

Litebit

Incident posture

Attack window
Sep 2017
Location
Netherlands
Status
Historical
CIA posture
Available to members
Updated
2025-11-30 00:00

Linked entities

Victim
Litebit
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Dutch cryptocurrency broker experienced two data breaches within six weeks, with the second incident involving unauthorized access to its backend systems. Attackers compromised customer data including email addresses, hashed passwords, IBAN information, payment methods, addresses, and phone numbers, though no funds were stolen in either breach. The company reported both incidents to Dutch authorities, attributing the compromises to issues with a supplier rather than direct infrastructure vulnerabilities. Following the breaches, users were advised to change passwords and reset two-factor authentication settings. The repeated security failures raised concerns about the broker's operational resilience amid increasing targeting of centralized cryptocurrency services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Litebit.eu, a prominent Dutch cryptocurrency broker, experienced two separate data breaches within a six-week period in 2017, with the second incident confirmed on September 12. The first breach occurred in August 2017 and was disclosed by the company as a "potential" compromise of customer accounts, though no funds were stolen. Approximately six weeks later, attackers successfully infiltrated Litebit's backend systems on September 12, gaining unauthorized access to customer databases containing email addresses, hashed passwords, and International Bank Account Number (IBAN) information. The breach did not result in theft of cryptocurrency funds or compromise of wallet security. Litebit promptly reported both incidents to Dutch law enforcement authorities and the national Data Protection Authority, though investigation outcomes remained undisclosed at the time of reporting.

The September breach specifically exposed personally identifiable information including payment methods, physical addresses, and phone numbers alongside the compromised credentials and banking details. In response to both incidents, Litebit advised affected users to immediately change their account passwords and reset two-factor authentication (2FA) configurations. The company attributed the security failures to vulnerabilities involving a third-party supplier rather than direct compromises of their core systems. These consecutive breaches impacted a significant portion of Litebit's customer base given its position as one of the Netherlands' largest cryptocurrency brokers. The repeated security incidents raised concerns about the broker's operational resilience despite no financial losses occurring, with the company maintaining transparency through public disclosures and regulatory notifications throughout both events.

Sources

Sources available to members: 1 source.

CSIDB