The Canadian Virtual Exchange (Cavirtex) service decided to cease operations on March 20, 2015, following an internal investigation that concluded that there may have been unauthorized access to an older version of its database.
The service is not entirely certain that sensitive information available on its infrastructure has been compromised, but even so, it acknowledged its inability to guarantee the confidentiality of its users' account credentials.
In an official statement on Tuesday, Cavirtex said that the potentially compromised database included two-factor authentication (2FA) credentials and hashed passwords. The related identification documents are not stored in the same location, otherwise the impact on customers would be significantly greater.
“We believe that the damage to the company’s reputation caused by the potential breach will significantly harm our ability to continue to operate successfully,” the official statement informs.
The incident was discovered on Sunday, but it is unclear when it actually occurred. The company is urging its customers to log into their accounts and change their passwords, as well as remove Cavirtex cookies in their web browsers .
On the other hand, Cavirtex says that it is solvent and that none of the client funds it manages have ever been lost. Therefore, clients should have no reason to worry about not receiving all of their money.
Refund requests received by March 25 will be processed without exception, the agency says, while all transactions should stop on March 20.
In another announcement on Thursday, Cavirtex said that restrictions from its payment provider prevented it from processing direct deposits greater than $150,000/€132,000 daily, and that withdrawals can “take at least 5 days longer than usual.”.
During this process, the service wants to make sure that the money ends up with its rightful owner and advises customers to report if they receive email confirmations for transactions they did not make.
The reason for this is that cybercriminals who were informed about the incident may try to exploit the situation and target Cavirtex customers through phishing attacks.

