Bitcoin IRA and iTrustCapital suffer data breaches linked to threat actor Tiffanny Milanovich

1 hour ago 16

Two of the most prominent crypto retirement account platforms, BitcoinIRA and iTrustCapital, have been hit by data breaches that enabled a wave of social engineering attacks, with on-chain sleuth ZachXBT linking the incidents to a US-based threat actor named Tiffany Milanovich. The damage so far: at least $5 million in stolen cryptocurrency.

One victim alone lost $1.2 million in Bitcoin and Ethereum after receiving a spoofed email that appeared to come from BitcoinIRA. Neither company has publicly acknowledged or commented on the breaches.

How the attacks worked

Evidence uncovered by ZachXBT suggests that Milanovich gained unauthorized access to customer databases at both BitcoinIRA and iTrustCapital, giving her the raw material needed to run highly targeted phishing campaigns.

Armed with personal details, Milanovich allegedly impersonated customer support representatives. She sent fraudulent emails designed to look like official platform communications, then followed up with phone calls. The goal was classic social engineering: trick victims into revealing private keys and seed phrases.

In one particularly costly incident in June, a victim received what appeared to be a legitimate email from BitcoinIRA. The spoofed message led to the theft of $1.2 million worth of Bitcoin and Ethereum.

A growing epidemic of impersonation fraud

These breaches don’t exist in isolation. The FBI logged 80,000 complaints related to tech-support impersonation in 2025, with losses totaling $2.9 billion. Chainalysis has tracked a staggering 1,400% increase in such scams over recent years.

ZachXBT’s investigation attributed at least $5 million in total crypto thefts to Milanovich across both platforms.

Platform silence raises questions

As of mid-August, neither BitcoinIRA nor iTrustCapital has issued a public statement confirming the breaches, disclosing the scope of compromised data, or outlining remediation steps for affected customers.

US data breach notification laws vary by state, but most require companies to inform affected individuals within a reasonable timeframe. The SEC and state regulators have also been tightening expectations around cybersecurity disclosures for financial services firms, including those operating in the digital asset space.

What investors should watch for

The immediate takeaway for anyone holding assets on either platform is to treat any unsolicited communication, email, phone call, or text message, with extreme suspicion. No legitimate customer support representative will ever ask for your private keys or seed phrase.

Investors should enable two-factor authentication on every account connected to their crypto holdings, ideally using a hardware-based authenticator rather than SMS, which is vulnerable to SIM-swap attacks. Verifying any communication by independently navigating to the platform’s website or calling their published support number is basic hygiene that becomes critical in an environment where attackers already have your personal details.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article