CoinGecko reported that it experienced a data breach on 5 June 2024 via its third‑party email marketing provider GetResponse, exposing contact data for nearly 1.9 million users but not passwords or account credentials. The company has told users that CoinGecko accounts remain secure and that the main risk relates to potential phishing attempts using the leaked email data. According to CoinGecko’s security notice, the incident began when an attacker compromised a GetResponse employee’s account, which allowed them to access CoinGecko’s GetResponse environment. The attacker exported 1,916,596 contacts from CoinGecko’s email database and used another GetResponse client’s account (alj.associates) to send 23,723 phishing emails, though none were sent from CoinGecko’s own domain. Exposed data included users’ names (if provided), email addresses, IP addresses, locations of email opens, and metadata such as subscription plan and signup date, but did not include passwords or direct access to CoinGecko user accounts. CoinGecko has said it directly notified affected users by email, is working with GetResponse to investigate the breach, and is reviewing and tightening its security and vendor management practices. Security commentators note that the case underscores systemic risks in relying on third‑party SaaS providers for user communications and the importance for users to be wary of phishing emails that reference CoinGecko or appear related to their crypto activity.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on CoinGecko

Comments