Financial and risk advisory firm Kroll said it suffered a breach of bankruptly claimants’ records as a result of a malicious actor using a SIM-swapping attack to target a T-Mobile US account belonging to a Kroll employee.Kroll said in a security incident notification posted on its website on Friday that the incident it suffered on 19th August occurred after T-Mobile transferred the phone number of one of its employees to the threat actor’s phone at their request.“We were recently informed that on Saturday, August 19, 2023, a cyber threat actor targeted a T-Mobile US., Inc. account belonging to a Kroll employee in a highly sophisticated “SIM swapping” attack. Specifically, T-Mobile, without any authority from or contact with Kroll or its employee, transferred that employee’s phone number to the threat actor’s phone at their request,” the company explained.After gaining access to the employee’s phone number, the threat actor subsequently gained access to bankruptcy claims information associated with three clients of the company - BlockFi, FTX and Genesis.Kroll facilitates bankruptcy claims for these insolvent companies. It said it took action to secure these accounts and impacted individuals have been notified about the incident.Kroll said it is also working with the FBI to investigate the matter and that it found no evidence to suggest that Kroll systems or accounts were affected by the cyber security incident."Across our firm, we continue to prioritize data security and information protection. We deeply regret any inconvenience or concern this situation may have caused and we will continue to prioritise the safety and trust of our clients, partners and community," the risk advisory firm said.The firm also advised clients that it would never ask them to link a cryptocurrency wallet to a website or application, share their seed phrase or private keys, download any software or use a particular wallet application, or provide passwords over text, email, or over the phone.The company also said that it does not share customers’ personal information, such as their social security numbers or birthdays, over email and customers should remain wary of such information being shared over online communication channels.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543