Curriculum·G705 Scam Response for Community Leaders·about 31 min

After: the second wave and the postmortem

By the end of this lesson you can

  • State what happened in the Kroll breach of August 2023, whose data was exposed, how, and what followed within days
  • Explain why an incident's data becomes the next incident's target list, and why the postmortem has to cover the second wave as well as the first
  • Compute the second-wave exposure of a creditor population from the breach's own scope, and read what the phishing that followed was worth
  • Write a postmortem the Academy's way: the timeline, the cause stated as a decision point, the changes, what members can verify, and what remains unknown

Graduate · enrolled learners

This lesson opens with The Kroll SIM-swap breach, 19 August 2023.

What happened
Kroll, the claims agent handling the bankruptcies of FTX, BlockFi and Genesis, reported that on 19 August 2023 an attacker had transferred a Kroll employee's phone number to their own device through the employee's carrier, T-Mobile, without any authority from or contact with Kroll or the employee. With the number, the attacker accessed files containing personal information of creditors of the three bankrupt platforms. For FTX customers that included names, addresses, email addresses, phone numbers, claim numbers and amounts, account identifiers and holdings; for Genesis and BlockFi creditors, names, addresses, emails and claim details. Account passwords and the platforms' own systems were not affected. Within days of the notifications, FTX creditors reported receiving phishing emails claiming they were eligible to begin withdrawing funds from their FTX accounts, and Genesis warned its creditors that the stolen information could be used for phishing and other scams.
The decision point
The breach exposed no money. It exposed a list: who had lost how much to which collapse, with the email address each of them would open a message about it at. That list is worth more to an attacker than any single wallet, because per G704-04 a person who has lost money is the easiest person to sell recovery to, and the phishing that arrived within days was built from the claim amounts themselves. A postmortem that ends at the first incident has not accounted for the thing the first incident produced. The Academy's postmortem form covers both: what happened, what it produced, what changed, what members can verify, and what is still not known.

What you will be able to answer

  • What happened in the Kroll breach?
  • Why is an incident's data the next incident's target list?
  • The postmortem's six parts?
  • What makes a postmortem an autopsy?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Terms used here

Sources and review

Confidence high·Volatility low·Reviewed 2026-09-14·Owner unassigned

Contested

Kroll did not publish the number of creditors whose data was accessed; the population of the three bankruptcies is in the hundreds of thousands and the lesson's worked example uses an illustrative fraction, labeled as such. Losses from the phishing that followed were not aggregated in any public source the lesson could find.

The lesson uses a claims agent rather than a community because it is the cleanest documented case of a breach whose only product was a target list. The structure is identical for a community incident thread.