BitcoinIRA and iTrustCapital Face Allegations of Concealing Data Breaches
Two prominent crypto retirement account platforms, BitcoinIRA and iTrustCapital, are facing serious allegations of data breaches that have reportedly led to over $5 million in stolen cryptocurrency. On-chain investigator ZachXBT has linked these breaches to a US-based threat actor named Tiffany Milanovich, who allegedly gained unauthorized access to customer databases.
The breaches have enabled a series of social engineering attacks, with victims receiving spoofed emails that appeared to originate from BitcoinIRA. One victim alone lost $1.2 million in Bitcoin and Ethereum due to a fraudulent email that tricked them into revealing sensitive information.
Despite the severity of the situation, neither BitcoinIRA nor iTrustCapital has publicly acknowledged the breaches or provided details on the compromised data. As of mid-August, both companies remained silent on the incidents, raising concerns about their transparency and compliance with US data breach notification laws.
ZachXBT's investigation revealed that Milanovich used personal details obtained from the breaches to impersonate customer support representatives, facilitating targeted phishing campaigns. This incident reflects a growing trend in impersonation fraud, with the FBI reporting 80,000 complaints related to tech-support impersonation in 2025, resulting in losses of $2.9 billion.
In response to the allegations, iTrustCapital claimed it had not experienced any data breaches, stating that its systems are designed to mitigate losses from potential scams. BitcoinIRA has yet to issue a public statement.
Investors are advised to be cautious and treat unsolicited communications with skepticism, as legitimate customer support will never request private keys or seed phrases. Enabling two-factor authentication and verifying communications through official channels are critical steps to protect assets in light of these breaches.
FAQ
What allegations are BitcoinIRA and iTrustCapital facing?
Both companies are facing allegations of data breaches that reportedly resulted in over $5 million in stolen cryptocurrency, linked to unauthorized access by a threat actor.
Who is Tiffany Milanovich and what is her connection to the breaches?
Tiffany Milanovich is a US-based threat actor identified by on-chain investigator ZachXBT, who allegedly gained unauthorized access to customer databases of BitcoinIRA and iTrustCapital.
What types of attacks have resulted from these data breaches?
The breaches have led to social engineering attacks, including phishing campaigns where victims received spoofed emails that appeared to be from BitcoinIRA, tricking them into revealing sensitive information.
Have BitcoinIRA and iTrustCapital acknowledged the data breaches?
As of mid-August, neither BitcoinIRA nor iTrustCapital has publicly acknowledged the breaches or provided details about the compromised data.
What steps can investors take to protect their assets in light of these breaches?
Investors are advised to treat unsolicited communications with skepticism, enable two-factor authentication, and verify communications through official channels, as legitimate customer support will never request private keys or seed phrases.
Comments
Comments are moderated before publish.
No comments yet — be the first.