Resurfaced in 2026 by investigators including @KrollWire: a seemingly "unsophisticated" T-Mobile SIM swap against a Kroll employee in August 2023 did not end with a press release and credit monitoring—it cascaded into phishing and SIM-swap campaigns that community and investigator estimates place at $300 million or more stolen from FTX, BlockFi, and Genesis bankruptcy creditors, with little public accountability for the original attacker.
The original breach — August 19, 2023
Kroll—a restructuring administrator hired to run claims portals for collapsed crypto platforms—confirmed that on August 19, 2023 someone targeted a Kroll employee's T-Mobile account in a SIM-swapping attack:
"T-Mobile, without any authority from or contact with Kroll or its employees, transferred that employee's phone number to the threat actor's phone at their request."
The attacker accessed files containing personal information of bankruptcy claimants in the BlockFi, FTX, and Genesis matters. FTX and BlockFi disclosed the breach within days; Genesis privately notified customers per CoinDesk reporting.
Kroll stated the FBI was involved and that no evidence suggested broader Kroll system compromise. The irony was immediate: a firm marketing "elite cyber risk leaders" lost control of creditor PII through a carrier port-out on a employee handset.
Within hours: phishing at scale
KrebsOnSecurity documented FTX-themed phishing the same morning breach notices landed—emails claiming creditors could "begin withdrawing digital assets from your FTX account" with links to credential-harvesting sites. BlockFi issued warnings about rising phishing as estate withdrawals opened.
The downstream theft wave — millions to $300M+
The initial SIM swap exposed names and contact data—not seed phrases. Criminals weaponized that trust context:
- March 2024: Help Net Security reported BlockFi creditors lost millions in five days to polished phishing impersonating BlockFi's withdrawal process; researchers tied some email lists to unrelated breaches but Kroll-timed campaigns clearly exploited bankruptcy context.
- Investigator estimates: Blockchain analyst ZachXBT and others cite eight- to nine-figure aggregate losses from post-Kroll phishing and social engineering against FTX, BlockFi, and Genesis creditors.
- 2026 discourse: Security commentators including @KrollWire aggregate downstream thefts above $300 million, emphasizing that the SIM swapper faced negligible public consequences relative to creditor harm.
BreachHistory indexes dollar figures as investigator/community estimates—not a unified regulatory finding. The directional truth is clear: a low-sophistication carrier fraud unlocked high-sophistication victim targeting against people already in financial distress.
Legal fallout — servicing, not just hacking
A 2026 putative class action (Hall Attorneys v. Kroll) alleges that after the known impersonation wave, Kroll continued rights-critical bankruptcy deadlines via email-only outreach without mailed confirmations or manual fallbacks—amplifying phishing losses, KYC lockouts, and expunged claims. Whether courts agree, the complaint frames a lesson beyond SIM swaps: incident response must include communication-channel hardening, especially when victims are already being impersonated.
Why creditors were uniquely vulnerable
- Financial desperation — Bankruptcy claimants awaited restitution; urgency overrides skepticism.
- Legitimate Kroll branding — Official notices primed victims to trust Kroll-adjacent email domains.
- Crypto wallet workflows — Phishing that requests wallet connections or seed phrases bypasses traditional bank fraud controls.
- SMS as identity — Many platforms still treat phone numbers as recovery anchors—the same weakness that compromised Kroll's employee.
Lessons for 2026 defenders
- Ban SMS-only 2FA for workforce and customer portals handling high-value claims—especially restructuring and crypto estates.
- Carrier hardening: SIM swap PINs, number-lock programs, and non-mobile FIDO2 for admin access.
- Multi-channel breach notice: Email + postal mail for any rights-affecting deadline after a contact-data breach.
- Assume downstream fraud: When a claims administrator is hit, pre-write anti-phishing guidance with signed, verifiable portal URLs only.
- Track supply-chain administrators — Kroll was tier-0 for three mega-bankruptcies; vendor risk assessments must cover restructuring firms, not just SaaS.
What affected creditors should still do
If you were an FTX, BlockFi, or Genesis claimant who received Kroll notices in 2023:
- Never connect wallets via email links—use only bookmarked official claims portals.
- Report impersonation to FBI IC3 and estate counsel.
- Document portal lockouts or disputed claims if pursuing legal remedies.
Bottom line
The Kroll SIM swap is a case study in second-order breach harm: a single carrier failure at a bankruptcy administrator allegedly enabled hundreds of millions in creditor theft through social engineering—while the original attack vector looked almost trivial. BreachHistory catalogs the 2023 disclosure separately from unverified dollar totals, but the incident belongs in every 2026 supply-chain and identity lesson plan.
Canonical record: Kroll SIM swap 2023 on BreachHistory.
Sources: Kroll, KrebsOnSecurity, The Record, Help Net Security