I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…
Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
281–290 of 550 posts
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#282Earlier quoted context omitted.
The Crypto industry continues their speedrun of rediscovering all of the reasons for why the global financial system exists. What you've described is the same thing that many Crypto enthusiasts call a "Bank"
Coinbase is identical to a bank because it holds customer funds. Your comment isn't quite the dunk you think it is. Blockchains allow money to be held anonymously without any banks involved. Centralized exchanges are just profiting on speculation and probably should be banned.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#283The problem is that it seems like the data that leaked is also the data that would be used to do account recovery. And what that means is that 1) If you lose access to your account (through either your own fault, or coinbases fault) that the process of recovering it may not be so straightforward anymore. 2) Hackers can try to “recover” accounts now using this leaked info. This is a huge problem. What coinbase needs a…
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#284Coinbase seems to be going to great lengths to try and distance themselves from the so-called "rogue overseas support agents". If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. Reimbursing duped customers makes sense, as it seems like they would have a pretty straightforward case to make in court that Coinbase's…
This seems like a strange interpretation. If an employee at your company, against policy and likely illegally extracts proprietary data and gives it to hackers in exchange for money you can hardly say that "My company sold it's data".
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#285Earlier quoted context omitted.
It’s my biggest gripe. They can pretty accurately flag a number as Spam or Telemarketing but in the “Silence Unknown Callers” setting I can only silence every single unknown caller. I can’t silence every single number that’s not in my contacts. When the plumber calls to confirm he’s in route, my phone needs to ring. Stuff like that.
iphone has been enshittified for several years now, it seems apple engineers are not using their own phones any more. I can understand it - when you're a millionaire just from your corporate job you won't be a stressed power user of your own iphones.
It’s sad because this seems like such a low hanging fruit for a big improvement. At some point in the relatively recent past, they added the indicator of the caller being a spammer or telemarketer. Seems like that would have been a good time to also enhance this filter but it seems nobody ever connected the dots on that one. Or if I’m being even more cynical, some engineer actually decided he’d rather everyone see his work on every incoming spam call instead of his work quietly improving everyone’s experience
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#286I'm having de ja vu here. If they only found out when they attempted to extort them does it mean they don't even bother to log employee access? Is there any means for accountability at all internally? It would be so simple to have access tracking and flag or lock out rogue employees... I look forward to seeing what the golden parachutes look like.
Looking at their blog post, it seems like they paid customer support agents to hand over sensitive data. The attackers did not have access to any agent accounts themselves, and the customer service agents were accessing data they were already privileged to anyways. https://www.coinbase.com/blog/protecting-our-customers-stand...
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#287The problem is that it seems like the data that leaked is also the data that would be used to do account recovery. And what that means is that 1) If you lose access to your account (through either your own fault, or coinbases fault) that the process of recovering it may not be so straightforward anymore. 2) Hackers can try to “recover” accounts now using this leaked info. This is a huge problem. What coinbase needs a…
> The only solution here is: hardware 2 factor like yubikeys. And when that’s lost, what do you do? Aren’t you back to account recovery step?
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#288Coinbase seems to be going to great lengths to try and distance themselves from the so-called "rogue overseas support agents". If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. Reimbursing duped customers makes sense, as it seems like they would have a pretty straightforward case to make in court that Coinbase's…
>If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. This seems like a strange interpretation. If an employee at your company, against policy and likely illegally extracts proprietary data and gives it to hackers in exchange for money you can hardly say that "My company sold it's data".
I once applied for a bank position, and they wanted to run a credit check. If you're in a position of handling money, the company has a responsibility to vet its employees. Do I agree with credit checks? Absolutely not, but the point is, Coinbase is partially responsible and that's why they're refunding duped customers.
How far that responsibility goes is up for debate.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#289Earlier quoted context omitted.
The Crypto industry continues their speedrun of rediscovering all of the reasons for why the global financial system exists. What you've described is the same thing that many Crypto enthusiasts call a "Bank"
except banks staff can easily be bribed too. There is plenty of bank fraud happening.
Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
#290Earlier quoted context omitted.
no-reply is a good practice. No business should ever encourage their customers to reply to the emails they are sending out. That's what scammers do. To contact the company you should go to company website at the address you know (which shouldn't be given in email as well), log in and send a message through internal message system, possibly referring to the email that you recieved through a random code (those can be a…
> No business should ever encourage their customers to reply to the emails they are sending out. It’s fascinating that we keep creating new technology and then find out that in practice most of it cannot be trusted. Which means it cannot be used for anything serious. IT revolution is a bit of a failure
Some of these technologies that have been mass adopted because they're easily accessible also have glaring security holes and ways to be exploited built into them. It's a tale as old as time, and I can hardly blame businesses in this specific case (using no-reply addresses.)