Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

301–310 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#301

I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

Why do you see this as the fault of Coinbase? Do other companies somehow have employees that are immune to bribes and blackmail?

This is due to US Government KYC laws that forced Coinbase to associate government identification with all accounts. No crypto company required ID until they were forced to.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#302

Earlier quoted context omitted.

It’s my biggest gripe. They can pretty accurately flag a number as Spam or Telemarketing but in the “Silence Unknown Callers” setting I can only silence every single unknown caller. I can’t silence every single number that’s not in my contacts. When the plumber calls to confirm he’s in route, my phone needs to ring. Stuff like that.

iphone has been enshittified for several years now, it seems apple engineers are not using their own phones any more. I can understand it - when you're a millionaire just from your corporate job you won't be a stressed power user of your own iphones.

That seems...overly dramatic. Further, enshittification as a concept generally refers to VC/growth-hacking style situations.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#303
post #115

Earlier quoted context omitted.

You can take the Google approach of basically not empowering the agents at all. It's not worth trying to social engineer Google CS, because they can't do anything anyway.

Coinbase has the same approach. It's a miracle that ransomware operators got in touch with Coinbase support at all.

It would be pretty simple actually

>Go on LinkedIn

>Look up profiles of people who work at Coinbase

>Contact and bribe them with a burner account

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#304
post #148
post #59

Earlier quoted context omitted.

> What coinbase needs are IRL offices where you can go and do things like account recovery, and where people trying to steal money can be caught and prosecuted (and makes a huge barrier for the overseas thieves who are usually doing this) That's just a bank.

Watching crypto enthusiasts run into every problem that society already tackled with in the past when developing currency and its controls, and then coming up with solutions that look exactly the same as what dirty fiat currency uses, has been a source of much entertainment the past few years

> every problem that society already tackled with in the past

More KYC creates more problems while solving some others. Why didn't the same society despite KYC/AML tackle the problem pointed at in a previous comment? "Florida teens kidnap Las Vegas man, drive him to Arizona desert, steal $4M in cryptocurrency"[1] Why is there this crime?

Without mandatory KYC laws, this particular attack would be near pointless. No name tied to account, bookkeeping doesn't archive wire transaction details for the past 10 years.

Let businesses easily accept cryptocurrency (like... regular cash?), without a blade to their throat held by the government, and the need for such centralization points will greatly diminish. People get in trouble by p2p-exchanging money with unknown peers; in some instances this "trouble" has the unit of "years".

It's in nobodies' interest to protect cryptocurrency payments as the alternative, other than the activists, and the big groups jumping in on it for the speculation purposes - something they had refined decades ago. There's CBDC is on the horizon.

[1]: https://news.ycombinator.com/item?id=43999011

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#305

Earlier quoted context omitted.

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

Why do you see this as the fault of Coinbase? Do other companies somehow have employees that are immune to bribes and blackmail? This is due to US Government KYC laws that forced Coinbase to associate government identification with all accounts. No crypto company required ID until they were forced to.

You don't think Coinbase is responsible for restricting access to member data for support agents?

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#306
post #238

I'm having de ja vu here. If they only found out when they attempted to extort them does it mean they don't even bother to log employee access? Is there any means for accountability at all internally? It would be so simple to have access tracking and flag or lock out rogue employees... I look forward to seeing what the golden parachutes look like.

I built the admin panel used by internal employees and contractors at a major fintech payments processor (PCI Level 1). We had to add multiple levels of safety once we decided to hire a team outside of our US office including logging, monitoring and also rate-limiting (ask for manager to approve if more than 5 full details requests, etc.) I think these requirements are much stringent due to PCI-DSS standards for credit card processors. I wonder if a lack of such standards in crypto makes the companies holding customer funds more lax.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#307

Coinbase seems to be going to great lengths to try and distance themselves from the so-called "rogue overseas support agents". If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. Reimbursing duped customers makes sense, as it seems like they would have a pretty straightforward case to make in court that Coinbase's…

>If they were Coinbase employees or contractors, that means the company basically sold its own data to hackers, who then turned around and demanded a ransom. This seems like a strange interpretation. If an employee at your company, against policy and likely illegally extracts proprietary data and gives it to hackers in exchange for money you can hardly say that "My company sold it's data".

> This seems like a strange interpretation. If an employee at your company, against policy and likely illegally extracts proprietary data and gives it to hackers in exchange for money you can hardly say that "My company sold it's data".

When an employee ships a new feature, do you say "My company shipped a new feature?"

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#308

I tried to reach out to coinbase customer support to see if I was impacted. Once I wasted my time with the AI bot and got a human they were unaware of the breach. I was the first person to inform them about it.

They emailed impacted accounts. Source: I was impacted

I don't believe they did, and I also believe they have known about this issue for a long time, and they should have been required to disclose their mandatory 8k a lot earlier.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#309
post #148

Earlier quoted context omitted.

Watching crypto enthusiasts run into every problem that society already tackled with in the past when developing currency and its controls, and then coming up with solutions that look exactly the same as what dirty fiat currency uses, has been a source of much entertainment the past few years

As I understand, the root of the problem is that Coinbase kept lot of sensitive information, including photos of IDs. If Coinbase was fully anonymous, and didn't require any KYC, the impact of the leak would be insignificant because it would be difficult to link user number 12345 with some real-world person. So if we want to constrain impact of such attacks, we must make companies keep less data and delete them faste…

> store just a checkbox that the person showed their ID and it was valid.

Doesn't work at scale. You get bribes, rogue employees, socially engineered employees. In the US, look up the articles about phone/SIM unlocks and SIM card copies. Russia has a problem with e-signatures, that most people have no idea about. It's possible to sell somebody's real estate with one of these. Loans granted just based on passport data. Neither politics nor media highlight these issues. Overall in this case your suggestion tries to handle the symptoms of the KYC requirement.

Here's a more extreme treatment: let people change their full legal name at will. Gender's already kinda possible.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#310
post #277
post #238

I'm having de ja vu here. If they only found out when they attempted to extort them does it mean they don't even bother to log employee access? Is there any means for accountability at all internally? It would be so simple to have access tracking and flag or lock out rogue employees... I look forward to seeing what the golden parachutes look like.

Looking at their blog post, it seems like they paid customer support agents to hand over sensitive data. The attackers did not have access to any agent accounts themselves, and the customer service agents were accessing data they were already privileged to anyways. https://www.coinbase.com/blog/protecting-our-customers-stand...

The customer service agents were accessing data they were already privileged to anyways.

That's not how front line support agent access should work. You get access based on active cases you are working on, not the keys to the kingdom because you might need to support a member at some future point in time.

Post reply on HN