Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

131–140 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#131
Blog post is here:

https://www.coinbase.com/blog/protecting-our-customers-stand...

> We will reimburse customers who were tricked into sending funds to the attacker due to social engineering attacks. If your data was accessed, you have already received an email from no-reply@info.coinbase.com; all notifications went out at 7:20 a.m. ET on 5/15 to affected customers.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#133

And the reason Coinbase has to keep all that sensitive stuff, much more than what would be required to identify and authenticate you, which you hope will never be stolen, is because of know your customer laws, so you can thank your government that pictures of your passport got stolen and for whatever criminals and rogue Coinbase employees do with that info.

There are very good reasons for KYC, the problem here is not the government regulation, it's once again private companies being sloppy with their customer's data because sloppy is cheap and it's not their info on the line, it's yours, so there's little motivation for them to safeguard it _unless_ they're compelled to do it by law.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#134
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

[deleted]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#135
post #44

Interesting coincidence? >On April 12, Coinbase updated their user agreement to take effect TODAY, May 15, with new language about waiving some rights to class action lawsuits and jurisdiction selection. https://bsky.app/profile/jsweetli.bsky.social/post/3lp7sw647...

[deleted]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#136
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

[deleted]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#138
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

> Coinbase didn't adequately secure sensitive customer information, and it was leaked Practically every company has someone with credentials who is in some combination of debt, a damningly-adulterous relationship, a damningly-illegal substance relationship and/or feels underappreciated or slighted compensationwise. The question is generally how much it costs.

Which is exactly why insider threats should be explored as a threat-model and mitigated to make the blast radius as small as possible via rate PII sanitization, access controls, access monitoring, rate limiting, etc.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#139
post #65

Employees at Signal must be getting bribes as well, or even threats of violence since they can get nation state Secret communications these days. Got to make it so employees can’t do anything nefarious. This helps protect them.

How would employees of Signal access the encrypted messages?

They don’t need to.

Under specific conditions, the client can communicate with malware already on device, save data locally for other software to pick up, or downright stream the decrypted software to a third party.

Most likely is to introduce a flaw in the client that can be used by other walware on the client.

Clearly no red team members on HN these days.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#140
post #75
post #65

Earlier quoted context omitted.

How would employees of Signal access the encrypted messages?

Employees can't get access to encrypted messages. But they can look the other way about flaws in their Electron client.

Or any client.
Post reply on HN