Breaches · 179 days ago
North Korea–linked Lazarus Group compromised a Bitrefill employee laptop and drained funds from the company's hot wallets. Attackers exfiltrated about 18,500 purchase records containing email addresses, crypto payment addresses and IP metadata. Bitrefill says there is no evidence of a full database extraction, has largely restored services, and will absorb losses from operational capital.
2 sources covering this story
Bitrefill blames North Korean Lazarus group for cyberattack
Crypto-powered gift card store Bitrefill says that the attack it suffered at the beginning of the month was likely perpetrated by North Korean hackers of the Bluenoroff group.
The Record from Recorded Future
Crypto e-commerce platform Bitrefill accuses North Korea of stealing 18,500 purchase records
Bitrefill said hackers allegedly tied to North Korea’s Lazarus group accessed around 18,500 purchase records that contained email addresses, crypto payment addresses, and metadata including IP addresses.
Part of the PlainSec briefing for 2026-03-18