Israeli Investment Firm Mitbestrade Reports Customer Data Breach
Translated & summarized from Behadrei Haredim by baba
The story in 5 lines · by baba
- Mitbestrade customer data stolen via external API.
- Personal details including ID and bank info compromised.
- Passwords and financial data remained secure.
- Company blocked access and is contacting affected clients.
- External supplier and attacker identities unknown.
Israeli investment company Mitbestrade announced on Sunday that a data security incident resulted in the theft of personal customer information. The breach occurred through an API interface managed by an external supplier, and was discovered when customers began receiving unsolicited one-time verification codes on Saturday. Approximately 3,000 SMS messages containing these codes were sent as part of the incident. While several attempts were made to alter the phone numbers receiving the codes, these were unsuccessful.
The compromised data includes full names, ID numbers, bank account numbers, and beneficiary details where applicable. Mitbestrade emphasized that passwords, financial data, or identification documents were not exposed, and the attacker did not gain access to customer funds or trading systems. The company has since blocked access to the affected interface and ceased its use.
Two external audits have been conducted following the incident. Mitbestrade stated that it will personally contact all affected customers. The identity of the external supplier and the attacker, as well as the specific vulnerability exploited, have not yet been disclosed. The company estimates the incident is over and does not anticipate a significant impact on its operations, though this assessment may change.
Read the original at Behadrei HaredimMentioned
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.