Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

71–80 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#71
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

How can customer support operate without knowing anything about the customer?

You know how your bank asks you to verify details when you call?

Without the right details the customer support people don’t get entry into the customers account details.

Banks have been doing this for 30+ years..

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#72
post #64
post #52

Earlier quoted context omitted.

Bribes are one thing, but threats could also happen. This is a big part of the reason why I absolutely hate entities that think residential addresses should be public record. This is a precedent to Coinbase employees getting physical threats at their door just because e.g. some voter registration, utility company, bank, credit card, or court record decided to release their name and addresses on the internet. People c…

AFAICT it's impractical to keep residential addresses 100% private/secure - too many ways to get an address from any number of companies, organizations and governments that collect it for various reasons. Plus numerous ways to infer your address from other data sources, including apps that grab GPS on friends' cellphones when they visit, etc. Finally, shutting down paid data brokers seems virtually impossible in prac…

> shutting down paid data brokers seems virtually impossible in practice

Just jail them. Make it a felony to release someone's PII without their written consent, and make data brokers illegal to begin with.

> numerous ways to infer your address from other data sources, including apps that grab GPS on friends' cellphones when they visit

These are not the main vector of transmission of personal information. Yes, Meta could probably do some graph analysis and infer this, but it's a lot of work, and their data leaks are rare in comparison to all the other companies, financial institutions, and governmental organizations, that freely post residential addresses on the internet and to data brokers for the world to Google.

> companies, organizations and governments that collect it for various reasons

KYC requiring addresses should be banned. Companies should not collect a residential address.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#74
post #44

Interesting coincidence? >On April 12, Coinbase updated their user agreement to take effect TODAY, May 15, with new language about waiving some rights to class action lawsuits and jurisdiction selection. https://bsky.app/profile/jsweetli.bsky.social/post/3lp7sw647...

This should be illegal.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#75
post #65

Employees at Signal must be getting bribes as well, or even threats of violence since they can get nation state Secret communications these days. Got to make it so employees can’t do anything nefarious. This helps protect them.

How would employees of Signal access the encrypted messages?

Employees can't get access to encrypted messages.

But they can look the other way about flaws in their Electron client.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#76
post #36

Whatever you think of Coinbase, this is a pretty good response IMO: > and will not pay the $20 million ransom demand we received. Instead we are establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible

I’d say the better thing for customers would be to pay the ransom demand and get the PII back. If they want to fund a reward scheme too, well great, but if it were my data, I’d care more about Coinbase limiting the breach of the data, not playing around with retaliatory rewards.

Limiting? The damage is already done.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#78
post #24

Earlier quoted context omitted.

It's probably hard to keep call-center workers bribe-proof.

[flagged]

You are writing this as if you know what countries Coinbase's call centers are located in and the role of organized crime in their economies, but you don't actually know either of those things.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#79
post #36

Whatever you think of Coinbase, this is a pretty good response IMO: > and will not pay the $20 million ransom demand we received. Instead we are establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible

I’d say the better thing for customers would be to pay the ransom demand and get the PII back. If they want to fund a reward scheme too, well great, but if it were my data, I’d care more about Coinbase limiting the breach of the data, not playing around with retaliatory rewards.

There is no guarantee that an anonymous criminal is going to hold up their end of the agreement. Coinbase has no idea who they're negotiating with or where that data has been shared.

That, and they're reimbursing customers who were tricked.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#80
post #57

Earlier quoted context omitted.

The main point of crypto IMO is to have a large-denomination bearer asset. This is overlooked most places but if you examine around the time the FATF finally pretty much eliminated bearer bonds, bearer stocks, and large bank notes was exactly the time crypto really took off.

this? https://www.investopedia.com/terms/b/bearer-instrument.asp

yes. IIRC ~2015 was when the last of bearer bonds/shares were pretty much all completely immobilized. I can't recall when the last ~1000 USD equivalent banknotes were printed but it was also close to that time.
Post reply on HN