Skip to content

Gemini

Disclosed Dec 16, 20223 years ago5,274,214 accountsUnverified

In late 2022, a hacker posted a data set to a public hacking forum which they alleged was sourced from the Gemini crypto exchange , a claim that was later proven to be false as the data was traced back to an incident at a third-party vendor . The source of the breach was later established as being Twilio, who processed the data of some Gemini customers using their Authy service for 2FA. Twilio described the incident as stemming from a sophisticated social engineering attack designed to steal employee credentials .

What is known

People affected5,274,214 (accounts in the leaked data, per Have I Been Pwned)
DisclosedDec 16, 2022
HappenedDec 13, 2022
AttackVendor breach
Data exposedEmails, Phone numbers
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: Geminihaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataDec 16, 20225,274,214
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about Gemini

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.