Data Breach Exposes 1.5 Million Binance User Accounts

Data Breach Exposes 1.5 Million Binance User Accounts

First seen 29 Mar 2026, 22:14 UTC BeincryptoMexc.Co 64.5

Article Content

Browse articles
ThreatCluster

On March 28, 2026, cybersecurity platform VECERT reported that a threat actor named PexRat is selling a database containing the personal information of 1.5 million Binance users. The leaked data includes full names, email addresses, phone numbers, Know Your Customer (KYC) verification statuses, last-login IP addresses, device user agents, and two-factor authentication (2FA) statuses. The breach did not involve a direct attack on Binance's internal servers; instead, it was a result of a credential stuffing and scraping operation that bypassed security mechanisms. This incident follows a previous report in January 2026, which revealed around 420,000 Binance-linked credentials exposed via infostealer malware. The exposure of sensitive data poses significant risks, including vulnerability to SIM-swap attacks and phishing campaigns. Binance's growing institutional trading activities are now overshadowed by these security concerns, which could impact user trust and operational integrity.

Key Points: • 1.5 million Binance user accounts have had their data leaked for sale. • The breach was due to credential stuffing and scraping, not a direct server compromise. • Users are at risk of SIM-swap attacks and phishing due to exposed 2FA and KYC data.

Timeline

2026-01-01
Binance's OTC platform records 25% of total 2025 volume.
2026-01-10
Jeremiah Fowler reports 420,000 Binance-linked credentials exposed.
2026-03-28
VECERT reports data leak of 1.5 million Binance users.