A significant data breach has exposed the personal information of 1.5 million Binance users, according to cybersecurity platform VECERT. The leaked data includes full names, email addresses, phone numbers, and Know Your Customer (KYC) verification statuses. More concerningly, the breach also involves last-login IP addresses, device user agents, and two-factor authentication statuses, posing a severe risk of SIM-swap attacks and phishing campaigns. The breach, attributed to a threat actor known as PexRat, did not result from a direct server compromise. Instead, it involved a sophisticated credential stuffing and scraping operation that bypassed security mechanisms like Captcha. This incident follows a previous report of 420,000 Binance-linked credentials exposed via infostealer malware, highlighting ongoing challenges in Binance's cybersecurity measures.