Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

281–290 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#281

I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…

Where was the number from? I received an impressive number of phonecalls attempt but thankfully I never answer to unknown numbers. With google call screen they hung up everytime so I assume its a scam.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#282
post #262

Earlier quoted context omitted.

The Crypto industry continues their speedrun of rediscovering all of the reasons for why the global financial system exists. What you've described is the same thing that many Crypto enthusiasts call a "Bank"

Coinbase is identical to a bank because it holds customer funds. Your comment isn't quite the dunk you think it is. Blockchains allow money to be held anonymously without any banks involved. Centralized exchanges are just profiting on speculation and probably should be banned.

No they don’t. “Cryptocurrency” isn’t money at all. Just because you can trade it in for money, doesn’t make it so. I can also trade in my hat to the Buffalo Exchange for money. But my hat is not money.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#283

The problem is that it seems like the data that leaked is also the data that would be used to do account recovery. And what that means is that 1) If you lose access to your account (through either your own fault, or coinbases fault) that the process of recovering it may not be so straightforward anymore. 2) Hackers can try to “recover” accounts now using this leaked info. This is a huge problem. What coinbase needs a…

If you ever sent money to or from a wallet you control, I'd think a reliable recovery factor would be to use that key to sign a message that Coinbase can verify with the address in their records. Cryptocurrency after all is just another PKI.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#284

Coinbase seems to be going to great lengths to try and distance themselves from the so-called "rogue overseas support agents". If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. Reimbursing duped customers makes sense, as it seems like they would have a pretty straightforward case to make in court that Coinbase's…

>If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom.

This seems like a strange interpretation. If an employee at your company, against policy and likely illegally extracts proprietary data and gives it to hackers in exchange for money you can hardly say that "My company sold it's data".

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#285

Earlier quoted context omitted.

It’s my biggest gripe. They can pretty accurately flag a number as Spam or Telemarketing but in the “Silence Unknown Callers” setting I can only silence every single unknown caller. I can’t silence every single number that’s not in my contacts. When the plumber calls to confirm he’s in route, my phone needs to ring. Stuff like that.

iphone has been enshittified for several years now, it seems apple engineers are not using their own phones any more. I can understand it - when you're a millionaire just from your corporate job you won't be a stressed power user of your own iphones.

It’s not that it got worse, this feature has just never been great. It just feels half baked , which I agree a lot of Apple software has been trending towards. That said, what has increased is the volume of spam calls. So the importance of this feature has also increased.

It’s sad because this seems like such a low hanging fruit for a big improvement. At some point in the relatively recent past, they added the indicator of the caller being a spammer or telemarketer. Seems like that would have been a good time to also enhance this filter but it seems nobody ever connected the dots on that one. Or if I’m being even more cynical, some engineer actually decided he’d rather everyone see his work on every incoming spam call instead of his work quietly improving everyone’s experience

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#286
post #277
post #238

I'm having de ja vu here. If they only found out when they attempted to extort them does it mean they don't even bother to log employee access? Is there any means for accountability at all internally? It would be so simple to have access tracking and flag or lock out rogue employees... I look forward to seeing what the golden parachutes look like.

Looking at their blog post, it seems like they paid customer support agents to hand over sensitive data. The attackers did not have access to any agent accounts themselves, and the customer service agents were accessing data they were already privileged to anyways. https://www.coinbase.com/blog/protecting-our-customers-stand...

It makes me wonder what type of access support agents have in the first place. A lot of this information should require "unlocking" on a case-by-case basis by challenge/response while interacting with a customer.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#287

The problem is that it seems like the data that leaked is also the data that would be used to do account recovery. And what that means is that 1) If you lose access to your account (through either your own fault, or coinbases fault) that the process of recovering it may not be so straightforward anymore. 2) Hackers can try to “recover” accounts now using this leaked info. This is a huge problem. What coinbase needs a…

> The only solution here is: hardware 2 factor like yubikeys. And when that’s lost, what do you do? Aren’t you back to account recovery step?

Then you send your iris scan to sama

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#288

Coinbase seems to be going to great lengths to try and distance themselves from the so-called "rogue overseas support agents". If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. Reimbursing duped customers makes sense, as it seems like they would have a pretty straightforward case to make in court that Coinbase's…

>If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. This seems like a strange interpretation. If an employee at your company, against policy and likely illegally extracts proprietary data and gives it to hackers in exchange for money you can hardly say that "My company sold it's data".

In a way you can. A company is its employees. If you want employees with integrity you might need to pay better than bottom dollar employees from the cheapest countries possible.

I once applied for a bank position, and they wanted to run a credit check. If you're in a position of handling money, the company has a responsibility to vet its employees. Do I agree with credit checks? Absolutely not, but the point is, Coinbase is partially responsible and that's why they're refunding duped customers.

How far that responsibility goes is up for debate.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#289

Earlier quoted context omitted.

The Crypto industry continues their speedrun of rediscovering all of the reasons for why the global financial system exists. What you've described is the same thing that many Crypto enthusiasts call a "Bank"

except banks staff can easily be bribed too. There is plenty of bank fraud happening.

Can you show us that? Where the consumer is left with no money at all and bank does not take the loss.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#290

Earlier quoted context omitted.

no-reply is a good practice. No business should ever encourage their customers to reply to the emails they are sending out. That's what scammers do. To contact the company you should go to company website at the address you know (which shouldn't be given in email as well), log in and send a message through internal message system, possibly referring to the email that you recieved through a random code (those can be a…

> No business should ever encourage their customers to reply to the emails they are sending out. It’s fascinating that we keep creating new technology and then find out that in practice most of it cannot be trusted. Which means it cannot be used for anything serious. IT revolution is a bit of a failure

The first "email" was sent in the 1971 and SMTP was designed in 1983. Back then the implementers didn't dream of the adoption levels of these protocols that we see today. Your same complaint could be levied against the best practices for phone calls in order to avoid scams, and that's also a slightly older technology.

Some of these technologies that have been mass adopted because they're easily accessible also have glaring security holes and ways to be exploited built into them. It's a tale as old as time, and I can hardly blame businesses in this specific case (using no-reply addresses.)

Post reply on HN