2023 ConsenSys / MetaMask — third-party customer-support ticketing compromise (~7k support users)
Data compromised
Email addresses mandatory for support; optional user-entered PII in ticket bodies per ConsenSys FAQ
Technical writeup
ConsenSys disclosed that unauthorized actors compromised a third-party provider operating MetaMask’s customer-support ticketing system. Users who submitted tickets between August 1, 2021, and February 10, 2023, could have had contact data and free-text fields (sometimes including financial or identity snippets users volunteered) accessed; the vendor stated wallet software and browser extension integrity were unaffected. Approximately 7,000 users were notified, with reports to Irish and UK data-protection regulators.
Root cause
Third-party SaaS/provider breach enabling access to support ticket stores