Mexc.Co Data Breach Exposes 1.5 Million Binance User Accounts
Article Content
- •1.5 million Binance user accounts have had their data leaked for sale.
- •The breach was due to credential stuffing and scraping, not a direct server compromise.
- •Users are at risk of SIM-swap attacks and phishing due to exposed 2FA and KYC data.
On March 28, 2026, cybersecurity platform VECERT reported that a threat actor named PexRat is selling a database containing the personal information of 1.5 million Binance users. The leaked data includes full names, email addresses, phone numbers, Know Your Customer (KYC) verification statuses, last-login IP addresses, device user agents, and two-factor authentication (2FA) statuses. The breach did not involve a direct attack on Binance's internal servers; instead, it was a result of a credential stuffing and scraping operation that bypassed security mechanisms. This incident follows a previous report in January 2026, which revealed around 420,000 Binance-linked credentials exposed via infostealer malware. The exposure of sensitive data poses significant risks, including vulnerability to SIM-swap attacks and phishing campaigns. Binance's growing institutional trading activities are now overshadowed by these security concerns, which could impact user trust and operational integrity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track PexRat and Binance in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…