Sweden
SWE
On 1 March 2026, attackers compromised an employee laptop and used a legacy production credential to reach Bitrefill infrastructure, including parts of its database, cryptocurrency wallets and gift-card purchasing systems. Bitrefill detected suspicious supplier purchasing, drained hot wallets and exploitation of gift-card inventory, then took systems offline; its website and app were restored on 5 March. About 18,500 purchase records were accessed. Bitrefill said the malware, infrastructure and on-chain indicators showed strong similarities to prior Lazarus/BlueNoroff activity, but the attribution was presented as an assessment rather than definitive proof.
Estimated severity
77 / 100
Source reliability
86 / 100
Approximate Date
01/03/2026
Targeted Company
BITREFILL
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Sweden
SWE
No other affected countries reported
Target country
Sweden
Affected countries
Impacted regions
No information
Duration
4 days
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone