Skip to content
Data Breach Exposes 1.5 Million Binance User Accounts

Data Breach Exposes 1.5 Million Binance User Accounts

First seen 29 Mar 2026, 22:14 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 30, 2026 at 22:14 UTC
  • •1.5 million Binance user accounts have had their data leaked for sale.
  • •The breach was due to credential stuffing and scraping, not a direct server compromise.
  • •Users are at risk of SIM-swap attacks and phishing due to exposed 2FA and KYC data.

On March 28, 2026, cybersecurity platform VECERT reported that a threat actor named PexRat is selling a database containing the personal information of 1.5 million Binance users. The leaked data includes full names, email addresses, phone numbers, Know Your Customer (KYC) verification statuses, last-login IP addresses, device user agents, and two-factor authentication (2FA) statuses. The breach did not involve a direct attack on Binance's internal servers; instead, it was a result of a credential stuffing and scraping operation that bypassed security mechanisms. This incident follows a previous report in January 2026, which revealed around 420,000 Binance-linked credentials exposed via infostealer malware. The exposure of sensitive data poses significant risks, including vulnerability to SIM-swap attacks and phishing campaigns. Binance's growing institutional trading activities are now overshadowed by these security concerns, which could impact user trust and operational integrity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

Timeline

2026-01-01
Binance's OTC platform records 25% of total 2025 volume.
2026-01-10
Jeremiah Fowler reports 420,000 Binance-linked credentials exposed.
2026-03-28
VECERT reports data leak of 1.5 million Binance users.

More articles in this cluster (2)

Following this threat?

Track PexRat and Binance in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed