LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Gemini Data Breach (2022)

CRITICAL severityConfirmedHow we verify

Gemini Data Breach (2022): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·December 13, 2022

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Gemini Data Breach (2022)

Reported December 13, 2022. Approximately 5.3M people affected.

CRITICAL
Severity
5.3M
People affected
2
Data types exposed
December 13, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Gemini Data Breach (2022) (reported December 13, 2022) exposed Email addresses and Partial phone numbers belonging to roughly 5.3M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Gemini Data Breach (2022) breach?
5.3M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Supply-chain and third-party compromises have become a persistent feature of the modern threat landscape, especially for financial platforms that rely on specialised vendors for authentication and customer communications. Incidents of this kind often surface first as unverified dumps on public forums, leaving organisations and users to untangle what was actually exposed and by whom.

In December 2022 a data set alleged to belong to the cryptocurrency exchange Gemini was posted online. Subsequent investigation established that the material did not originate from Gemini itself but from a third-party vendor. Approximately 5.3 million people were affected; the confirmed data types were email addresses and partial phone numbers. The episode illustrates how quickly a vendor breach can be misattributed and why customers of crypto platforms remain exposed even when the primary firm is not the direct point of failure.

What happened

On or around 13 December 2022 a hacker posted a data set to a public hacking forum and claimed it had been taken from Gemini, the cryptocurrency exchange. That claim was later shown to be false. Investigators traced the data to an incident at Twilio, a third-party vendor that processed information for some Gemini customers through its Authy service, which is used for two-factor authentication. Twilio characterised the intrusion as a sophisticated social-engineering attack aimed at stealing employee credentials. Public reporting has not disclosed the precise technical method beyond that description, nor has it released a full forensic timeline. The number of people whose information appeared in the set is given as 5.3 million; the named data elements are email addresses and partial phone numbers.

How a breach like this happens

Incidents involving authentication vendors commonly begin with social engineering. Attackers craft convincing messages or calls that persuade an employee to reveal credentials or to approve a fraudulent access request. Once inside the vendor’s environment, the attacker can reach customer records that the vendor holds in the course of providing services such as SMS or app-based two-factor authentication. Because many companies outsource these functions, a single successful compromise can expose data belonging to multiple client organisations. The stolen material is then often packaged and offered or dumped on criminal forums, sometimes with an incorrect or exaggerated attribution intended to increase its perceived value. Defenders typically discover the exposure only after the data appears publicly or after the vendor completes its own investigation and notifies affected clients.

Gemini and its sector

Gemini is a cryptocurrency exchange that allows customers to buy, sell and store digital assets. Firms in this sector routinely hold account identifiers, contact details and authentication data so that users can secure their wallets and receive transaction alerts. Because crypto balances are bearer assets that can be transferred irreversibly, any leakage of contact or authentication-related information raises the risk of targeted phishing or account-takeover attempts. Reliance on specialised two-factor-authentication providers is standard industry practice; consequently a breach at one of those providers can affect customers even when the exchange’s own systems remain uncompromised. The consequential nature of such an event therefore stems less from the exchange’s direct security posture and more from the interconnected web of vendors that support modern financial platforms.

The information in question

The data types confirmed as exposed are email addresses and partial phone numbers. Public reporting does not list additional elements such as full phone numbers, passwords, government identifiers or wallet keys. Organisations of Gemini’s type typically maintain richer customer records—including full contact details, device information and authentication logs—but the exact contents of the set released in this incident remain limited to what has been publicly named. Because the material was first misattributed to Gemini and only later linked to Twilio’s Authy service, the precise scope of records tied solely to Gemini customers has not been further itemised in available disclosures.

Why it matters

Email addresses and partial phone numbers are sufficient building blocks for phishing and smishing campaigns. An attacker who knows that an address is associated with a cryptocurrency account can craft messages that appear to come from the exchange or from its authentication provider, increasing the chance that a recipient will click a malicious link or surrender additional credentials. For the individuals affected, the practical risk is therefore elevated social-engineering exposure rather than immediate theft of funds. For Gemini and similar platforms the incident underscores the reputational and operational cost of vendor breaches: customers may lose confidence, support teams face higher volumes of inquiries, and the firm must coordinate notifications and remediation with a third party whose security it does not directly control. No dollar loss figure or confirmed secondary fraud total has been publicly attached to this specific event.

What to do if you're exposed

If you maintained an account with Gemini or used Authy around the time of the incident, treat unsolicited messages that reference your email or partial phone number with caution. Verify any security alert by navigating directly to the official site or app rather than following embedded links. Enable stronger authentication options where available, and consider placing fraud alerts with relevant services if you notice suspicious activity. Readers can also run a free exposure scan of their email address to check whether their information has appeared in known breach data sets, which provides an additional early-warning signal beyond official notifications.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyGemini security record
74/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Gemini’s full breach history →

More recent breaches

RailYatri Data Breach (2022)December 26, 2022SevenRooms Data Breach (2022)December 11, 2022Activision Data Breach (2022)December 4, 2022CoinTracker Data Breach (2022)December 1, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the Gemini Data Breach (2022) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram