Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

41–50 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#41
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

[flagged]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#42
post #41
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

[flagged]

[deleted]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#44
Interesting coincidence?

>On April 12, Coinbase updated their user agreement to take effect TODAY, May 15, with new language about waiving some rights to class action lawsuits and jurisdiction selection.

https://bsky.app/profile/jsweetli.bsky.social/post/3lp7sw647...

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#45
post #40
post #24

Earlier quoted context omitted.

It's probably hard to keep call-center workers bribe-proof.

Pretty sure all the Big Banks use call centers and manage to avoid this.

They haven't:

https://www.americanbanker.com/news/call-centers-and-bank-br... "Call centers and bank branches are major fraud liabilities"

https://www.bai.org/banking-strategies/beating-crooks-at-cal... "Aite Group’s findings that 61 percent of fraud can be traced back to the [call] center are equally concerning, as is its prediction that contact center fraud loss will double by 2020."

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#46
post #39
post #32

Earlier quoted context omitted.

Call center workers who have access PII and financial abilities should probably be vetted a little bit better.

How are you going to vet people to find out if they're vulnerable to bribery? Offer them a bribe during their probationary period, during which they only have access to fake customer data?

You can do a background check, but the reality of the matter is that you pay citizens a living wage to do the work instead of offshore it into a country that pays pennies.

Bank tellers can take thousands out of the vault at any time and yet it seems it’s not a very big issue.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#47
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

How can customer support operate without knowing anything about the customer?

A shared or hashed secret would do it.

Plenty of exchanges don't know their customers, and in fact that is how they get their customers.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#48
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

How can customer support operate without knowing anything about the customer?

Isn't the whole point of crypto to keep PII out of it completely? If not, what is all this non-sense for exactly, other than the typical goals of pyramid schemes?

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#49
post #46
post #39

Earlier quoted context omitted.

How are you going to vet people to find out if they're vulnerable to bribery? Offer them a bribe during their probationary period, during which they only have access to fake customer data?

You can do a background check, but the reality of the matter is that you pay citizens a living wage to do the work instead of offshore it into a country that pays pennies. Bank tellers can take thousands out of the vault at any time and yet it seems it’s not a very big issue.

Bank tellers are constantly surveilled by cameras, security guards, and several-times-daily cash counting, and it's still easy to find accounts of them having stolen significant amounts of money before getting caught. These are all from within the last year:

Vannia Chatt: https://6abc.com/post/former-citizens-bank-teller-accused-st...

Karen Farrell Tigler: https://www.irs.gov/compliance/criminal-investigation/former...

Stephanie Rose Kilbert: https://people.com/bank-teller-stole-money-while-pretending-...

Derek Aut: https://www.justice.gov/usao-ma/pr/former-bank-teller-arrest... https://www.usatoday.com/story/news/nation/2025/03/28/boston...

Mountee Brown: https://www.justice.gov/usao-md/pr/maryland-bank-teller-plea...

Being US citizens doesn't make people incorruptible. In fact, many other countries are less corrupt than the US. Someone in this very thread reports having witnessed bank tellers getting bribed in one of those countries: https://news.ycombinator.com/item?id=43996765

I've been through a background check designed to screen out people who were vulnerable to bribery. They interviewed my friends and family from the previous several years to find out if I was secretly gay, cheated on my wife, gambled, drank too much, used illegal drugs, or had money problems for some other reason. It took about a year. I think it would be hard for a financial institution to be economically competitive doing that kind of thing with their call-center workers, because their customers can't tell if they're secure or not, just how much their services cost.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#50

There should be an ISO standard with respect to how much power and information that front line customer support agents have. The more information you need, like changing passwords or accessing personal information, should get forwarded to higher level customer support agents with better training and more monitoring. This way you can design customer support experience with as little exposure to security issues as poss…

They main defense against internal attacks is bookkeeping. Banks have been dealing with this for thousands of years. I recommend the corresponding chapter in Security Engineering by Ross Anderson: https://www.cl.cam.ac.uk/archive/rja14/Papers/SEv3-ch12.pdf
Post reply on HN