Earlier quoted context omitted.
I’d say the better thing for customers would be to pay the ransom demand and get the PII back. If they want to fund a reward scheme too, well great, but if it were my data, I’d care more about Coinbase limiting the breach of the data, not playing around with retaliatory rewards.
There is no guarantee that an anonymous criminal is going to hold up their end of the agreement. Coinbase has no idea who they're negotiating with or where that data has been shared. That, and they're reimbursing customers who were tricked.
Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
231–240 of 550 posts
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#232Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#233I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…
If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…
https://www.yahoo.com/news/florida-teens-kidnap-las-vegas-20...
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#234I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…
.. and are former employees of Coinbase .. oh! just imagining!!
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#235Earlier quoted context omitted.
Yes that's true, but no need to hold your crypto there as a permanent storage. Once your fiat is exchanged to crypto, immediately transfer the crypto to your private wallet.
This just trades the unsolved exchange hacking problem for the unsolved lost/stolen keys problem.
I don't think anyone claimed that crypto was un-losable or un-stealable. It's not magic.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#236Earlier quoted context omitted.
I just switched to iPhone from a pixel device and I’m shook by all the spam calls. How do iPhone users deal with this?
It’s my biggest gripe. They can pretty accurately flag a number as Spam or Telemarketing but in the “Silence Unknown Callers” setting I can only silence every single unknown caller. I can’t silence every single number that’s not in my contacts. When the plumber calls to confirm he’s in route, my phone needs to ring. Stuff like that.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#237Earlier quoted context omitted.
You seem to believe that AML/KYC regulation exists to benefit customers or to prevent or recover from account compromises. It does not, and I have no idea why you would think it does. Something like a Yubikey or iris-scanning stations could help to prevent Coinbase account compromises, but AML/KYC regulations do not require or even encourage them, though perhaps someday they will.
You... want to replace KYC with iris scanning stations ?
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#238It would be so simple to have access tracking and flag or lock out rogue employees... I look forward to seeing what the golden parachutes look like.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#239If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom.
Reimbursing duped customers makes sense, as it seems like they would have a pretty straightforward case to make in court that Coinbase's actions led to their loss.
I'm more curious if someone who feels the need to move, change banks, change their email, hire a security detail etc. could successfully sue the company to recover some or all of those costs.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#240From the Coinbase website: https://www.coinbase.com/en-de/blog/protecting-our-customers... What they got - Name, address, phone, and email - Masked Social Security (last 4 digits only) - Masked bank‑account numbers and some bank account identifiers - Government‑ID images (e.g., driver’s license, passport) - Account data (balance snapshots and transaction history) Wow. Why does customer support staff have access to im…
Who else would verify the user passports if not the customer support staff? Who verifies (and photocopies! in Asia and Europe) your passport at a hotel or car rental office?