Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

271–280 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#271
post #95

Earlier quoted context omitted.

You seem to believe that AML/KYC regulation exists to benefit customers or to prevent or recover from account compromises. It does not, and I have no idea why you would think it does. Something like a Yubikey or iris-scanning stations could help to prevent Coinbase account compromises, but AML/KYC regulations do not require or even encourage them, though perhaps someday they will.

You... want to replace KYC with iris scanning stations ?

That is know your eye, not know your customer.

Yeah I know eventually these will be linked by some data broker and will meld into the same thing.

But I compare it to using a fingerprint to unlock a password manager on your phone. That ain't KYC.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#272
post #256

Earlier quoted context omitted.

I just switched to iPhone from a pixel device and I’m shook by all the spam calls. How do iPhone users deal with this?

You turn off the notifications from unknown callers? How does Android handle it?

Sometimes you need to answer calls from unknown numbers.

Google's call screening feature picks up the phone before it rings and asks the caller why they're calling. If they actually give a good reason, then it shows you the reason as text and you can decide whether to hang up on them or answer. https://support.google.com/phoneapp/answer/9118387

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#273

From the Coinbase website: https://www.coinbase.com/en-de/blog/protecting-our-customers... What they got - Name, address, phone, and email - Masked Social Security (last 4 digits only) - Masked bank‑account numbers and some bank account identifiers - Government‑ID images (e.g., driver’s license, passport) - Account data (balance snapshots and transaction history) Wow. Why does customer support staff have access to im…

I always thought that the government ID photos were claimed to be wiped out immediately after document verification. Guess not.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#275

I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…

I wonder if some of that perfect accent might be ML.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#276

The problem is that it seems like the data that leaked is also the data that would be used to do account recovery. And what that means is that 1) If you lose access to your account (through either your own fault, or coinbases fault) that the process of recovering it may not be so straightforward anymore. 2) Hackers can try to “recover” accounts now using this leaked info. This is a huge problem. What coinbase needs a…

[deleted]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#277
post #238

I'm having de ja vu here. If they only found out when they attempted to extort them does it mean they don't even bother to log employee access? Is there any means for accountability at all internally? It would be so simple to have access tracking and flag or lock out rogue employees... I look forward to seeing what the golden parachutes look like.

Looking at their blog post, it seems like they paid customer support agents to hand over sensitive data. The attackers did not have access to any agent accounts themselves, and the customer service agents were accessing data they were already privileged to anyways.

https://www.coinbase.com/blog/protecting-our-customers-stand...

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#278
post #59

Earlier quoted context omitted.

> What coinbase needs are IRL offices where you can go and do things like account recovery, and where people trying to steal money can be caught and prosecuted (and makes a huge barrier for the overseas thieves who are usually doing this) That's just a bank.

Beyond the regulatory-dodge and crypto marketing explain to me how Coinbase is NOT a bank

Well, right now they’re applying for a charter which suggests they don’t think they’re a bank, but I can think of some other reasons, too.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#279
post #192

Earlier quoted context omitted.

Scams have gotten better since AI. Most of the common spelling mistakes are gone. I was looking through some phishing e-mails the other day out of curiosity and found a weird unicode character mistranslated. Immediately knew it was an artifact of bad translation. So they're not perfect, but they're damn good.

The common spelling mistakes are there for a reason most of the time.

> a reason

Because people who read the message and think it's professionally written despite the spelling errors have a large overlap with people who will fall for the scam, at least far enough that money is transferred.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#280

From the Coinbase website: https://www.coinbase.com/en-de/blog/protecting-our-customers... What they got - Name, address, phone, and email - Masked Social Security (last 4 digits only) - Masked bank‑account numbers and some bank account identifiers - Government‑ID images (e.g., driver’s license, passport) - Account data (balance snapshots and transaction history) Wow. Why does customer support staff have access to im…

I always thought that the government ID photos were claimed to be wiped out immediately after document verification. Guess not.

The attackers bribed customer service agents to hand over data and documents, they were not breached directly. It's possible this stuff may have been handed over before being destroyed.
Post reply on HN