OpenSea Phishing Alert Follows Massive Email Data Breach
A rogue employee at email vendor Customer.io steals and shares OpenSea user email addresses with an external bad actor, prompting a widespread phishing warning.
OpenSea warns its users about potential phishing attacks after a massive data breach exposes their email addresses. A senior engineer at Customer.io, an email vendor contracted by OpenSea, misuses their system access to download and share user data with an unauthorized external party. Because of this leak, OpenSea advises anyone who has ever shared their email address with the marketplace to assume they are impacted.
Customer.io reports that the breach stems from the deliberate actions of a single employee who abuses their role-specific access privileges. The vendor terminates the responsible individual, removes all their system access, and reports the incident to law enforcement. Furthermore, Customer.io discovers that the same bad actor receives email addresses from five other unnamed client companies through this insider threat.
This incident highlights the growing cybersecurity risks facing crypto startups as the industry experiences explosive growth. In response to the breach, Customer.io revamps its security policies to prevent authorized personnel from downloading customer data. The company also introduces a new toggle feature that allows client companies to completely restrict employee access to end-user data or enable it only for a specific, limited time.