Skip to content

Bitcoin Platform Bitrefill Hacked by North Koreans

Bitrefill Cyberattack Linked to North Korean Hacking Groups

  • On March 1, Bitrefill experienced a cyberattack initiated by a compromised employee laptop.
  • The attack exposed approximately 18,500 purchase records with limited data fields accessed.
  • Indicators suggest involvement of North Korean groups Lazarus and Bluenoroff based on malware patterns and reused infrastructure.
  • Most operations have been restored, with losses covered by operational capital.

Bitrefill disclosed the cyberattack details after initially reporting a technical issue on March 1. The breach involved access to parts of its database and certain cryptocurrency wallets, with no full database exfiltration confirmed.

The company has tightened security measures following the incident, while working with law enforcement and cybersecurity experts to investigate further. Source

Share