Gemini
Disclosed Dec 16, 20223 years ago5,274,214 accountsUnverified
In late 2022, a hacker posted a data set to a public hacking forum which they alleged was sourced from the Gemini crypto exchange , a claim that was later proven to be false as the data was traced back to an incident at a third-party vendor . The source of the breach was later established as being Twilio, who processed the data of some Gemini customers using their Authy service for 2FA. Twilio described the incident as stemming from a sophisticated social engineering attack designed to steal employee credentials .
What is known
| People affected | 5,274,214 (accounts in the leaked data, per Have I Been Pwned) |
|---|---|
| Disclosed | Dec 16, 2022 |
| Happened | Dec 13, 2022 |
| Attack | Vendor breach |
| Data exposed | Emails, Phone numbers |
| Sector | Tech |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Geminihaveibeenpwned.com · Aggregator | Aggregator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Have I Been Pwnedaccounts in the data | Dec 16, 2022 | 5,274,214 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.