Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

401–410 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#403
> The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities

Based on the information present in the breach, I think it's likely that the source was their customer support in the Philippines. Monthly salary is usually > •Name, address, phone, and email; •Masked Social Security (last 4 digits only); •Masked bank-account numbers and some bank account identifiers; •Government‑ID images (e.g., driver’s license, passport); •Account data (balance snapshots and transaction history); and •Limited corporate data (including documents, training material, and communications available to support agents).

This is every threat actor's dream. Even if you only had email addresses and account balances, this is a nightmare. Instead of blackmailing the company, you can now blackmail each individual user. "Send me 50% of your BTC and I won't publish all of your information on the internet". My guess is that we will have a similar situation like we had with the Vastaamo data breach...

https://en.wikipedia.org/wiki/Vastaamo_data_breach

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#404

> the Company has preliminarily estimated expenses to be within the range of approximately $180 million to $400 million relating to remediation costs Hopefully companies take this as a lesson about bottom dollar outsourcing your CS. For those amounts, they could afford to have hired regionally local support agents, and paid them well over industry standard...

HA! Good one. They won't.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#405

> the Company has preliminarily estimated expenses to be within the range of approximately $180 million to $400 million relating to remediation costs Hopefully companies take this as a lesson about bottom dollar outsourcing your CS. For those amounts, they could afford to have hired regionally local support agents, and paid them well over industry standard...

The global trend is racing to the bottom, so even if they could, every business consultant or MBA would push them to rather put more AI agents instead. Because that's all what matters (to them). Did anybody learn anything out of this? Of course not.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#406

> the Company has preliminarily estimated expenses to be within the range of approximately $180 million to $400 million relating to remediation costs Hopefully companies take this as a lesson about bottom dollar outsourcing your CS. For those amounts, they could afford to have hired regionally local support agents, and paid them well over industry standard...

But do they consider it a CS risk or a business-wide risk? Is there any role at CoinBase that isn’t susceptible to insider risk? I would argue they would treat it as a security department / business risk issue and not a CS-only issue.

Onshoring CS and paying some more for that role may result in a net change of 0 risk (eg. The same possibility of a breach over the same time interval).

Would a lower class (for that region) Alabama man have less the susceptibility to insider risk as a middle class (for that region) Philippino man?

Most likely, the company will focus on better segmentation and better adherence to least permissions for all roles.

Also, your logic is clouded by the fact that you know it happened. In all aspects of security/cybersecurity, risk is incredibly difficult to calculate because you have to accurately know how much a counterfactual would cost in order to accurately choose one option over the other.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#407
post #393

Earlier quoted context omitted.

Companies should seriously consider implementing GDPR even in the US, it certainly made taking data dumps of customer data a lot harder and certainly private images like Government IDs were encrypted on disk. I’m surprised at the lack of security if I’m honest, at Yahoo! almost nobody had access to prod user data. Essentially you cannot trust Coinbase IMO, might move the few hundred dollars of BTC out of there :-)

> Companies should seriously consider implementing GDPR even in the US ... and save the data in US cloud where everybody can access it. It is really funny how FAANG can get away with data colkection in spite of GDPR.

Yeah this is really frustrating, especially the way the EU commission keep coming up with workarounds that the court will almost certainly strike down.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#408

> The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities Based on the information present in the breach, I think it's likely that the source was their customer support in the Philippines. Monthly…

> •Name, address, phone, and email;\

> blackmail each individual user

Blackmail would be the least of my worries, in France we had at least five kidnappings/attempted kidnappings related to crypto investors since the beginning of the year.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#410
post #248

Earlier quoted context omitted.

When was the last time your passport was copied in Europe? I don't think that this is still legal under the GDPR.

September 2024

In which country? What were the circumstances?
Post reply on HN