Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

481–490 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#481
post #473

Earlier quoted context omitted.

My money in the bank in case of fraud is protected unless I voluntarily gave the fraudster my money. If a bank goes bankrupt, my money is protected by the government

First one might be kind true in the US. Second one is only true up to $250k and how much Yellen likes you. But they are not true around the world and probably for most of it.

By law yes it’s only $250K. But when the banks collapsed last year, the government made sure that no one lost money. In fact, no one has ever lost money because of an FDIC insured bank failure.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#482

I tried to reach out to coinbase customer support to see if I was impacted. Once I wasted my time with the AI bot and got a human they were unaware of the breach. I was the first person to inform them about it.

They emailed impacted accounts. Source: I was impacted

Not sure what to say about that, I had an account with them, but I couldn't verify it, had email, phone and could be some sort of ID scanned - don't remember. Haven't used the account ever since and had nothing there, since January I have been getting regularly calls about my account being "compromised". This leak probably happened way earlier, because there was no way someone knew I had an account there and knew exactly the email I had with them.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#483
post #425

A few days ago I missed a delivery from UPS (in the UK). The next day I got a text from an unrecognised cell phone that just said “Hello” and didn’t respond further. The day after that I got a scam call (another UK cell number) from someone trying to hack into my Amazon account. They wanted me to supply the OTP code that Amazon texts you for 2FA. Anyway I eventually tracked down my package (it was at a convenience st…

Not sure how you relate your UPS delivery with the scam call? Just because it happened the following day you expected a delivery? I could be just a coincidence. I'm sure scammer's got get your phone number from many other sources and data breaches.

It could have been a coincidence, but I don’t receive deliveries often, and I don’t get scam calls often, so the timing and circumstances make it highly suspicious.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#484

Whatever you think of Coinbase, this is a pretty good response IMO: > and will not pay the $20 million ransom demand we received. Instead we are establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible

No it isn’t! The headline they used is “Protecting Our Customers - Standing Up to Extortionists.” My issue with it is that they word their announcement in a way that leads people to congratulate them instead of saying we’re sorry for leaking your private information. I’m so angry at them over this.

Additionally the email they sent me had the subject “important notice” and that my personal account was affected as the third sentence in a rather wordy paragraph. None of this is ok and this is not a company taking this seriously.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#485
post #458

Earlier quoted context omitted.

You can easily establish the connection from a bank account to a person. A connection from a crypto wallet to a person is extremely difficult. Money laundering with crypto is also much easier (and cheaper usually).

In the vast majority of cases, it's actually extremely easy. It took less than an afternoon for me to learn how to trace 90%+ of transactions on either BTC or any of the networks built on Ethereum or an Ethereum-like protocol. There are large companies that specialize in exactly this, which make tools that allow government agents who have no particular crypto expertise to trace the majority of transactions. It is pos…

You can trace the BTC or Ethereal transaction of coins, but you cannot trace the criminals after it's converted to Monero or some other "privacy" chain on an exchange run on the dark web. After that you're just tracing other owners, possibly who have no idea where that it was stolen. It literally takes a few hours to wash it all out.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#486
post #365

Earlier quoted context omitted.

And yet, Coinbase goes Scott free Someone, someone at that company should be going to prison for negligence

Can you point to a specific law that was broken where prosecutors have a chance at jail time, or is this a fantasy of yours?

The comment said "should be" which you glibly interpret as "should be going to jail based on the law" but could very easily be "the law should be such that this kind of negligence results in jail time".

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#487
post #336

Earlier quoted context omitted.

Unfortunately blocking all unknown calls is the only way to sanity. Otherwise we're talking 6-9 calls coming in ALL DAY, EVERY DAY. The calls are coming from new numbers, across multiple area codes. A few months ago I would have advised using Begone ( https://apps.apple.com/us/app/begone-spam-call-blocker/id159... ) to block but that only worked since these calls were isolated to blocks of area codes that were pretty…

answer the call and immediately put it on mute. they will hang up and stop calling

Don't you have caller-pays in the US?

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#488

Earlier quoted context omitted.

> Crypto isn’t synonymous with anarchy, just like the internet isn’t synonymous with pornography. Both are cliches from long ago. Saying crypto isn’t synonymous with anarchy, like the internet isn’t with pornography, sidesteps the point. Pornography is just one use of the internet — not its central purpose. But crypto wasn’t just built to host financial activity — it was designed to restructure it, removing reliance…

That's not what it was designed for, that's just a mixture of propaganda and confusion. It was designed to solve the double-spending problem with digital currencies, replacing the need for "a authoritative ledger" with a one difficult to forge. The political project around this was to provide people with a deflationary currency akin to gold, whose inflation could not be controlled by government. The lack of governmen…

It was designed to avoid the need for existing financial institutions. The doublespend problem was merely the blocker that prevented people from otherwise doing it.

> A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#489
post #327

Earlier quoted context omitted.

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

They said less than 1% of users were affected.

I thought this was 1% of user data, which could include names and addresses of all their members.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#490
post #475

Earlier quoted context omitted.

When I was "hacked" two years ago, their final hurrah before I finally got everything offline for a time, they sent zelles as much as they could and was able to recover it without any loss on my end.

I guess things have changed since it has not always been the case that the bank would reimburse you. https://www.nytimes.com/2022/03/06/business/payments-fraud-z...

Yeah, I think it truly depends on whether you hit the send button or not. Since I was hacked, it wasn't me hitting the send button.
Post reply on HN