Byte Federal Hack: 58,000 Bitcoin ATM Users’ Data Exposed
Florida-based crypto kiosk operator Byte Federal has suffered a major security breach, exposing the highly sensitive personal data of approximately 58,000 customers across the United States after hackers exploited a third-party software vulnerability.
What Sensitive Information Was Compromised?
According to an official filing submitted to Maine’s attorney general, the unauthorized intruders targeted a massive trove of customer records. The compromised data includes full names, physical addresses, telephone numbers, government-issued identification documents, Social Security numbers, detailed transaction histories, and user photographs.
How the Security Vulnerability Was Exploited
The cyberattack originally occurred on September 30, but Byte Federal did not detect the unauthorized network access until November 18. Investigators revealed that the malicious actor penetrated the company’s systems by exploiting a known security flaw within a third-party developer platform. In a blog post in November, the firm confirmed that the exploited bug was located in GitLab, a widely used collaborative software development tool.
Current Security Measures and Impact
Byte Federal runs a network of more than 1,200 physical Bitcoin ATMs throughout the United States, allowing consumers to buy and sell various digital assets. In response to the incident, the company has initiated a mandatory hard reset for all registered user accounts and executed a comprehensive update of all internal system passwords to secure its infrastructure against further unauthorized access.
