MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Bitrefill cyberattack forces platform shutdown and disrupts gift-card supply systems

On 1 March 2026, attackers compromised an employee laptop and used a legacy production credential to reach Bitrefill infrastructure, including parts of its database, cryptocurrency wallets and gift-card purchasing systems. Bitrefill detected suspicious supplier purchasing, drained hot wallets and exploitation of gift-card inventory, then took systems offline; its website and app were restored on 5 March. About 18,500 purchase records were accessed. Bitrefill said the malware, infrastructure and on-chain indicators showed strong similarities to prior Lazarus/BlueNoroff activity, but the attribution was presented as an assessment rather than definitive proof.

77

Estimated severity

77 / 100

86

Source reliability

86 / 100

Approximate Date

01/03/2026

Targeted Company

BITREFILL

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Sweden

SWE

Other Affected Countries

No other affected countries reported

Target country

Sweden

Affected countries

Sweden

Impacted regions

No information

Operational Impact

Duration

4 days

Financial impact (USD M)

No information

Impact types

Service unavailabilityOperational disruptionInventory or distribution impactOrder processing disruptionSupply chain coordination disruption

Affected sectors

Retail

Affected departments

Information TechnologyInventory ManagementProcurement & SourcingOrder ManagementSales

Attack Profile

Attack types

MalwareUse of stolen credentialsUnauthorized accessData exfiltration

Attributed threat actors

LAZARUS GROUPBLUENOROFF

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.