Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

511–520 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#511
post #507

Earlier quoted context omitted.

“Hey, cryptocurrency exchange, I, a random rich person, would like to, having never interacted with you before, buy a million dollars of bitcoin and transfer it out. Today, please.” That is simply not going to happen.

Eh, million dollars would not raise a single eyebrow from an exchange side. Your bank, maybe, will have some questions about the transaction, but the things they can do to prevent you spending your money are thankfully fairly limited.

How long do you think it takes to create an account, get your KYC documents verified, get your trading and withdrawal limits raised to a million or more, transfer funds from your brokerage account, buy tokens and then re-verify when you try to transfer the tokens out of the exchange?

You'd be lucky to complete this in less than a week.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#512

Earlier quoted context omitted.

As opposed to the bank's ...? Or your other account's ..., what exactly, passwords? Phising is everywhere. How many times have you heard the elderly have their money stolen, both online and in real life? It happened to my grandma. The mailman is bringing her own pension as cash, and guess what, he has scammed my grandma for years! The food delivery guy who has been delivering lunch for my grandma, guess what he did?…

Hence why cryptocurrency would never replace regular banks for regular people. The situation with scams and thefts has only gotten worse. Not your keys, not your coin.

I definitely cannot imagine my grandma making use of crypto, or PayPal, or her bank's online site. :)

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#514

Earlier quoted context omitted.

As I understand, the root of the problem is that Coinbase kept lot of sensitive information, including photos of IDs. If Coinbase was fully anonymous, and didn't require any KYC, the impact of the leak would be insignificant because it would be difficult to link user number 12345 with some real-world person. So if we want to constrain impact of such attacks, we must make companies keep less data and delete them faste…

> store just a checkbox that the person showed their ID and it was valid. Doesn't work at scale. You get bribes, rogue employees, socially engineered employees. In the US, look up the articles about phone/SIM unlocks and SIM card copies. Russia has a problem with e-signatures, that most people have no idea about. It's possible to sell somebody's real estate with one of these. Loans granted just based on passport data…

In Russia one can change their name, although it is a lot of pain as you need to change it in all agreements (like bank agreement) and documents. So a better idea is simply not store customer names.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#515
post #346

Earlier quoted context omitted.

There are very good reasons for KYC, the problem here is not the government regulation, it's once again private companies being sloppy with their customer's data because sloppy is cheap and it's not their info on the line, it's yours, so there's little motivation for them to safeguard it _unless_ they're compelled to do it by law.

This is costing Coinbase $400M. They are well incentivized to prevent this.

Well their stock is up 6bn today

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#516
post #361

Earlier quoted context omitted.

> This seems like a strange interpretation. If an employee at your company, against policy and likely illegally extracts proprietary data and gives it to hackers in exchange for money you can hardly say that "My company sold it's data". When an employee ships a new feature, do you say "My company shipped a new feature?"

Did the employee ship the feature this against their employer's will? 'Cause if so, I'm not sure we would say the company shipped it.

If an Amazon Delivery driver murders someone in their home while working would we say "Amazon Murdered an Old Lady" ?

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#517

Saved dimes on customer support, lost $400m. It's hard to not believe in Karma sometimes.

> The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States

yea that is what they get. Hope this hurts them bad.

At my last job for a "casual dating" app, all new account verification stuff was sent to some shop in the Philippines. I got involved with troubleshooting some random DB locks that were causing down time. Ended up discovering that this firm tried to automate the verification process with some scripts or something that would sometimes go haywire and send over 100 requests per second to the new account admin portal which would bring down the entire site. Management just asked them nicely to be more careful which brought the peaks down to 80 requests per second which the back end seemed to be able to cope with (just barely). They couldn't careless that there were supposed to be humans looking at this data and they were clearly trying to automate that part out. Even worse, once I started looking at the data that was in the portal, it was credit card name and billing addresses, and DL license or passport scans. Before I could really further fix the performance issue, I was laid off. Then a few months later they did another lay off which cleaned out every american employee. This was an american company that had ~150 american employees and now there are none. Just two execs at the top that get to watch the money roll in while they farm out everything to overseas. Really pisses me off bad >:(

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#518
post #470
post #463

Earlier quoted context omitted.

Yeah, I know two French people who did it (one of them avoided UK taxes as he was paid in crypto while working in the UK, the other it's muddier). I know three people in the space, and only those two were on the financial side, so to me, while Blockchain is still a legit tech, anybody using cryptocurrency I peg as a tax evader.

Good thing we have courts, lawyers and judges for that. It’s funny everyone here hates on Trump but as soon as something align with their view, they want a defacto no due process application.

Sorry if i implied anything, i must have missed part of the conversation, i was just confirming that did happen (taking the portugese residency to avoid crypto tax) a few years ago. In my opinion, police should protect even violent criminals from violence when possible, so of course i'm not advocating for anything to happen on tax "avoiders", and they should be protected. I was just stating that i know people in the crypto space, and if you are, i immediately peg you as a small-time sociopath from my past experience.

Also i don't care about them getting judged for tax evasion, i know they won't be and honestly, good for them. I also don't care for nonviolent thieves and think the same thing about them. Profiteering was not how i was raised, but i understand different people have different standards (and parents, luckily mine are great, it's not the case for everybody). People do what they need to do, i found some comportment sociopathic, but as long as it is nonviolent, i'm not mad.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#519

> the Company has preliminarily estimated expenses to be within the range of approximately $180 million to $400 million relating to remediation costs Hopefully companies take this as a lesson about bottom dollar outsourcing your CS. For those amounts, they could afford to have hired regionally local support agents, and paid them well over industry standard...

But do they consider it a CS risk or a business-wide risk? Is there any role at CoinBase that isn’t susceptible to insider risk? I would argue they would treat it as a security department / business risk issue and not a CS-only issue. Onshoring CS and paying some more for that role may result in a net change of 0 risk (eg. The same possibility of a breach over the same time interval). Would a lower class (for that re…

>Would a lower class (for that region) Alabama man have less the susceptibility to insider risk as a middle class (for that region) Philippino man?

The american could be facing jail time, depending on the data. The Philippino man, not so much.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#520

Saved dimes on customer support, lost $400m. It's hard to not believe in Karma sometimes.

It will happen (at least attempted) with on-shore support staff too, My next door neighbour used to work for a UK high street bank and even there support staff were approached, with some of them first befriended, and eventually bribed in to passing along PII. No doubt it happens in the US too. Just costs the bad guys more.

Keeping things onshore means the offenders could face jail time. Anything offshore just goes into a blackhole.
Post reply on HN