Skip to content
General

Data leak: 1.9 mln Vietnam crypto app users at risk

By Sarah Chen
1 min read
Onus
Onus
In this article (4)

Personal data of 1.92 million users of Vietnamese digital currency app Onus has been leaked due to a security breach.

The Singapore-based company founded and managed by Vietnamese stated Monday its server had been attacked and personal data of a large number of users could have been leaked.

It added user assets were not affected by the attack.

Internet users on Dec. 25 found the data of Onus customers posted on a data trading website by an account named ‘vndcio.’

The data includes real name, email address, phone number, username and Electronic Know Your Customer (eKYC) info, which is the digital verification of an identity without the need for face-to-face interaction.

Of all 1.92 million Onus users, around 90 percent are Vietnamese, the hacker said.

‘vndcio’ claimed to have accessed the server of Onus to get the data and delete the files on the server afterward.

He or she also uploaded screenshots of the data, including passport and ID card info of users along with videos of 10 users’ faces, which is how Onus identify its customers.

The hacker did not reveal how much he or she charges for the data but provided an email address for contact.

On Dec. 26, another account, ‘blackblock1234,’ uploaded the same data with a total volume of nine terabytes.

The leaked data is enough for hackers to fake user identification or send them unwanted advertisements.

Onus, formally VNDC, launched its app in March last year and claimed to have 1.8 million users in over 20 economies, with over 600,000 of them having identified themselves electronically.

It allows users to trade cryptocurrencies like Bitcoin and manage their investments.

Questions & Answers

Q.

Which specific types of personal data belonging to Onus users have been compromised in this security breach?

A.

The leaked data includes users' real names, email addresses, phone numbers, usernames, and Electronic Know Your Customer (eKYC) information. The hacker also uploaded screenshots showing passport and ID card details, along with videos of users' faces.

Q.

What is the potential impact for users whose data has been leaked, according to the article?

A.

The leaked data provides enough information for other malicious actors to potentially fake user identification documents. It also creates an opportunity for users to be targeted with unwanted advertisements as a result of the breach.

Q.

How did Onus respond to the discovery of the data leak?

A.

Onus, a Singapore-based company, stated on Monday that its server had been attacked, acknowledging that a large number of user accounts could have been compromised. They also confirmed that user assets held within the app were not affected.

Reader pulse

What is the biggest concern?

19,725 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready