HackerFeeds
All breaches
gemini.com

Gemini data breach5.3M accounts compromised on 2022-12-13

Verified

Gemini (gemini.com) was the source of a data breach dated 2022-12-13, exposing 5,274,214 accounts. The details below are mirrored from Have I Been Pwned and reflect the source's account of the incident at the time of publication.

Incident Report

Target OrganizationGemini
Source NameGemini
Domaingemini.com
Breach Date2022-12-13
Added to HIBP2022-12-16
Last Modified2025-08-13
Accounts Compromised5,274,214(5.3M)
Data Exposed
Email addressesPartial phone numbers
Status
Verified by HIBP

Description

In late 2022, a hacker posted a data set to a public hacking forum which they alleged was sourced from the Gemini crypto exchange, a claim that was later proven to be false as the data was traced back to an incident at a third-party vendor. The source of the breach was later established as being Twilio, who processed the data of some Gemini customers using their Authy service for 2FA. Twilio described the incident as stemming from a sophisticated social engineering attack designed to steal employee credentials.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.