-
A seller on the dark web claims to have a customer database from crypto exchange Gemini, though no one has confirmed the data is real.
-
The alleged records reportedly include full names, email addresses, phone numbers, and location details, mostly tied to U.S. users.
-
Gemini has faced smaller data issues before, but its status page shows no new breach right now.

A seller on the dark web says they have a customer database tied to U.S. crypto exchange Gemini. The claim is raising fears about phishing and scam attempts against users. Still, nobody has confirmed that this data actually came from a fresh Gemini breach.
Darket threat alert accounts on X, such as Dark Web Intelligence, first flagged the listing. According to their report, an underground seller is advertising what they call a Gemini customer database. The seller claims the file holds full names, email addresses, phone numbers, and location details. Most of the people affected are supposedly based in the United States.
Nobody has checked this claim independently yet. The listing does not say when the data was taken. It also skips how many people are affected. There is no proof the information came straight from Gemini’s own systems. The records could be new, old, or pulled together from several older leaks.
A Look at Gemini’s Past Data Issues
This new claim matters more because of Gemini’s history. The company has dealt with a data problem before. Back in December 2022, Gemini said a third-party vendor was hit by an incident.
That event led to some customer email addresses and partial phone numbers being exposed, according to a breach record on Mozilla Monitor. Gemini said its own systems stayed safe. The company also said customer funds were never touched.
That older incident matters when people look at today’s claim. Leaked data often gets reused. Hackers frequently blend old records with new ones before reselling them. A leak from years ago can resurface looking brand new.
Gemini ran into another customer issue more recently too. Around September 2026, several users said they received a flood of emails meant for other customers. Reddit posts described emails packed with other people’s credit-card dispute details.
Some of those messages also exposed the email addresses of the people who received them by mistake. Even so, nothing ties that mix-up directly to the database the seller is advertising now.
No Sign of a New Confirmed Breach
Gemini keeps a public status page that lists ongoing issues. Right now, that page shows no confirmed customer-data breach tied to this new claim. Recent entries mostly cover service hiccups and connection problems.
During those past incidents, Gemini repeatedly said customer accounts and funds stayed secure, based on updates from its official status page.
The exchange also points to its safety setup on its security page. Gemini turns on two-factor authentication by default for every account. Users can add a hardware security key too. The platform also lets people lock down withdrawals to approved wallet addresses only.
Right now, this alleged sale should be treated as an unconfirmed claim. It is not solid proof that Gemini suffered a new breach. Still, if the data turns out to be real, it could cause real harm.
Dark web monitoring has also become an important part of how businesses track emerging threats. Google has deployed Gemini AI agents to monitor dark web activity, helping businesses identify potential threats and exposed information before they can cause greater damage.
Names, emails, and phone numbers give scammers plenty to work with. Criminals could use those details to build convincing phishing messages or fake support calls.
Gemini Warns Users, Urges Them to Look Out for Scams
The company shared tips on spotting fake messages in a blog post about phishing protection. Anyone who thinks their account might be compromised should reach out to Gemini support right away. The company lays out exact steps to take in its account security guide.
For now, no trusted source has confirmed this database is real. Nobody has verified its size either. Nobody knows exactly where it came from. Until someone proves otherwise, this stays an unconfirmed threat-actor claim, not a confirmed breach.
Users who trade on Gemini should still stay alert. Turn on every security feature the platform offers. Watch out for emails or calls asking for personal details. Real companies rarely ask for sensitive information over email. If a message feels off, do not click anything inside it. Instead, go straight to the official site and check with support directly.
Stolen data, real or not, tends to spread fast once it hits dark web forums. Buyers trade it, combine it with other leaks, and resell it again later. Staying cautious now costs little. Ignoring a possible leak could cost a lot more down the road. Keep an eye on account activity, question anything unusual, and treat unexpected messages with a healthy dose of doubt until they are proven safe.