Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

121–130 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#121
And the reason Coinbase has to keep all that sensitive stuff, much more than what would be required to identify and authenticate you, which you hope will never be stolen, is because of know your customer laws, so you can thank your government that pictures of your passport got stolen and for whatever criminals and rogue Coinbase employees do with that info.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#122
post #48

Earlier quoted context omitted.

How can customer support operate without knowing anything about the customer?

Isn't the whole point of crypto to keep PII out of it completely? If not, what is all this non-sense for exactly, other than the typical goals of pyramid schemes?

It's simple. They want to centralize crypto and dickheads like armstrong are happy to be in line to make that happen. Just look at tether, what's the point of it? It's nothing but a front for inflating the price of bitcoin. It has NEVER been audited and has been found to NOT have any USD backing at all

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#123
post #52
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

Bribes are one thing, but threats could also happen. This is a big part of the reason why I absolutely hate entities that think residential addresses should be public record. This is a precedent to Coinbase employees getting physical threats at their door just because e.g. some voter registration, utility company, bank, credit card, or court record decided to release their name and addresses on the internet. People c…

This is a feature of bitcoin not a bug.

If you sling code for cryptocurrency you and your loved ones are "in the game" now.

https://www.bbc.com/news/articles/c20qee5030do

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#124
So this is probably why the phishing calls have increased from ~1 per month to ~3 per week.. good to know... Wish coinbase would let me DO something about it... Maybe fresh accounts for everyone? Maybe KYC data not directly linked to accounts? There should be SOMETHING they can do because the sheer volume of people constantly harassing CB customers is nuts.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#125
post #115
post #24

Earlier quoted context omitted.

It's probably hard to keep call-center workers bribe-proof.

You can take the Google approach of basically not empowering the agents at all. It's not worth trying to social engineer Google CS, because they can't do anything anyway.

Coinbase has the same approach. It's a miracle that ransomware operators got in touch with Coinbase support at all.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#126
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

> Coinbase didn't adequately secure sensitive customer information, and it was leaked

Practically every company has someone with credentials who is in some combination of debt, a damningly-adulterous relationship, a damningly-illegal substance relationship and/or feels underappreciated or slighted compensationwise. The question is generally how much it costs.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#127
post #113

Earlier quoted context omitted.

Let me add to your statement. It is hard to keep call center workers bribe-proof WHEN they are paid peanuts AND they are working for a company that is in an extremely high risk business of managing crypto.

correct, but what's the alternative? they're paid peanuts because it's not exactly the kind of job you ever pay out the wazoo for. the only thing that comes to mind if I'm Brian Armstrong is going all in on AI bots that can get to 90% of the way there (maybe 95%) and then have domestic based humans that are paid more with (presumably) a less probability of being bribed. but realistically, the only way to stop somethi…

> what's the alternative?

Small set of privileged employees who work from the home office and are compensated to match. If an issue requires their attention, it takes time to resolve. But it's resolved securely. In essence, what Google does.

Alternative is the banking model. Low-cost customer service massively empowered and just eat the costs of breaches as they come.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#128
post #84

[flagged]

> if you don't have sole control of your cryptocurrency keys then you don't own any cryptocurrency

Nobody has sole control of their cryptocurrency by definition. It's a consensus protocol. (On a practical level, there are always layers of trust.)

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#129

From the Coinbase website: https://www.coinbase.com/en-de/blog/protecting-our-customers... What they got - Name, address, phone, and email - Masked Social Security (last 4 digits only) - Masked bank‑account numbers and some bank account identifiers - Government‑ID images (e.g., driver’s license, passport) - Account data (balance snapshots and transaction history) Wow. Why does customer support staff have access to im…

Ah, cool. My name, home address, phone number, social security number, and images of my drivers license and passport as well as what bank I use.
Post reply on HN