Crypto firm fined $67k over data leak affecting 650,000

Data stolen from exchange operator Quoine included addresses, NRIC and passport scans

Sign up now: Get ST's newsletters delivered to your inbox

Virtual currency exchange operator Quoine has been fined $67,000 for failing to protect the personal data of more than 650,000 customers, in what is believed to be the first breach of the Personal Data Protection Act (PDPA) involving a cryptocurrency firm here.
The stolen data included full names, addresses, e-mail addresses, phone numbers and various kinds of documents such as photos and scans of NRICs and passports belonging to customers.
Financial information about Quoine's Japanese customers, and transaction information and bank account details, were also leaked.
In a written decision published last Thursday, Singapore's privacy watchdog said Quoine had failed to review and assess the security implications and risks of a development and operations (DevOps) account used by a criminal to access the data. The company had also failed to implement reasonable controls for the account, added the Personal Data Protection Commission (PDPC).
Quoine, which operates crypto exchange Liquid, collected and stored the data for the purpose of know-your-client checks.
The breach occurred in November 2020 after a staff member at a third-party domain provider engaged by Quoine fell for a social engineering attack and incorrectly transferred control of the domain hosting account to the culprit.
A domain provider allows one to purchase and register a website domain name, which was quoine.com in Quoine's case.
PDPC did not specify what kind of social engineering attack was used, but the culprit was able to change the registered e-mail address on the domain hosting account and take control after resetting the password.
This enabled the culprit to redirect all e-mails from Quoine's e-mail service to another server.
The culprit then reset the password to one of Quoine's DevOps accounts, which was mainly used for automation tasks, meaning human employees did not regularly use the account. The DevOps account was then used to access Quoine's cloud databases and steal the customer data inside.
PDPC found that Quoine bore responsibility for the poor security of the DevOps account.
"The organisation suggested that the DevOps account's security risk profile had not been assessed, probably due to its intended use as an automation account. This was not accepted," the commission said.
"The organisation is not exempted from assessing the security implications and risks of the DevOps account simply on the basis that it was an automation account, especially considering that the DevOps account could be used to access the customer data stored in the databases."
Quoine notified its customers of the breach and advised them to take actions to secure their accounts and check for suspicious activities. It also moved its domains to a more robust service provider with stronger access controls, including mandatory two-factor authentication.
Quoine also migrated its Liquid exchange to a different vendor's cloud platform and implemented additional safeguards such as IP address whitelist restrictions, which ensures certain accounts can be logged into only from specific networks.
PDPC said it took into account that Quoine took prompt remedial actions. It was cooperative during investigations and voluntarily accepted liability for the incident, the commission added.
See more on