I tried to reach out to coinbase customer support to see if I was impacted. Once I wasted my time with the AI bot and got a human they were unaware of the breach. I was the first person to inform them about it.
They emailed impacted accounts. Source: I was impacted
Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
241–250 of 550 posts
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#242Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#243Earlier quoted context omitted.
Yes, I think I’m familiar with the crypto enthusiasts defenses that all boil down to looking at a single aspect of their system in a vacuum and not realizing that if anyone wants to functionally use crypto as a currency and not as a speculative asset or tool in crime, then all these aspects actually have to work and work together
I don't really care about crypto personally (volatile shitcoins) but I think that's a straw man argument. They all know it gets troublesome when it comes to dealing with fiat transactions. The hardcore crypto enthusiasts want to avoid fiat entirely.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#244Earlier quoted context omitted.
They emailed impacted accounts. Source: I was impacted
Was this the general "Important Notice" email that went out this morning, or something more specific.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#245I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…
I just switched to iPhone from a pixel device and I’m shook by all the spam calls. How do iPhone users deal with this?
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#246Earlier quoted context omitted.
I hope they are serious about paying the reward, and aren’t planning to rug-pull it. They could always pay it in crypto.
It might not be a bad idea for the various crypto exchanges to pool their resources into a non-denominational security organization. It could offer hardening services, and some kind of accreditation. It would also make many Ponzi schemes easier to spot, as they wouldn’t want to contribute.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#247Earlier quoted context omitted.
I just switched to iPhone from a pixel device and I’m shook by all the spam calls. How do iPhone users deal with this?
I don’t get any calls, seems to be an US problem?
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#248Earlier quoted context omitted.
Who else would verify the user passports if not the customer support staff? Who verifies (and photocopies! in Asia and Europe) your passport at a hotel or car rental office?
When was the last time your passport was copied in Europe? I don't think that this is still legal under the GDPR.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#249I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…
I started getting regular Coinbase login confirmation codes text messages with no attempts on my end Same with my Microsoft account actually I usually just ignore it but I assume someone is testing if my email can be used to login.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#250Earlier quoted context omitted.
How would employees of Signal access the encrypted messages?
They don’t need to. Under specific conditions, the client can communicate with malware already on device, save data locally for other software to pick up, or downright stream the decrypted software to a third party. Most likely is to introduce a flaw in the client that can be used by other walware on the client. Clearly no red team members on HN these days.