Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

91–100 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#91
post #46
post #39

Earlier quoted context omitted.

How are you going to vet people to find out if they're vulnerable to bribery? Offer them a bribe during their probationary period, during which they only have access to fake customer data?

You can do a background check, but the reality of the matter is that you pay citizens a living wage to do the work instead of offshore it into a country that pays pennies. Bank tellers can take thousands out of the vault at any time and yet it seems it’s not a very big issue.

> you pay citizens a living wage to do the work instead of offshore

But what about the capital class? How will they afford more yachts? So sad. They're.. um... job creators or something. Anyway, that's what Fox News told me.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#92
post #88
post #78

Earlier quoted context omitted.

You are writing this as if you know what countries Coinbase's call centers are located in and the role of organized crime in their economies, but you don't actually know either of those things.

Lol, that's because while Coinbase emphasizes its commitment to security and compliance specific details about the geographic distribution of its offshore personnel are not disclosed in its public filings.

My perspective was more "That's because you post contentious statements in public fora with no reason to believe that they are true, hoping to get a big reaction by offending people."

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#93

From the Coinbase website: https://www.coinbase.com/en-de/blog/protecting-our-customers... What they got - Name, address, phone, and email - Masked Social Security (last 4 digits only) - Masked bank‑account numbers and some bank account identifiers - Government‑ID images (e.g., driver’s license, passport) - Account data (balance snapshots and transaction history) Wow. Why does customer support staff have access to im…

I also like 'last 4 digits only' as if that's not the most important parts and the part so many places use to validate your identity, the first 5 are just area and group so they're not exactly random.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#94
post #64
post #52

Earlier quoted context omitted.

Bribes are one thing, but threats could also happen. This is a big part of the reason why I absolutely hate entities that think residential addresses should be public record. This is a precedent to Coinbase employees getting physical threats at their door just because e.g. some voter registration, utility company, bank, credit card, or court record decided to release their name and addresses on the internet. People c…

AFAICT it's impractical to keep residential addresses 100% private/secure - too many ways to get an address from any number of companies, organizations and governments that collect it for various reasons. Plus numerous ways to infer your address from other data sources, including apps that grab GPS on friends' cellphones when they visit, etc. Finally, shutting down paid data brokers seems virtually impossible in prac…

Man, I hate how Wisconsin makes the data not only public, but free.

I bought a house here after a long time out of country and the first year all I got for mail was scam bullshit. Loads of it.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#95
post #66

It's really unfortunate that KYC regulations required Coinbase to have this information in the first place. We should be establishing strong social norms against sharing PII without a legitimate reason; this is not just an individual theft risk but a national security risk. Coinbase doesn't pay into your Social Security account, so they shouldn't have your Social Security number. They don't visit your house, so they…

Let's hear you repeat this position after your Coinbase account is compromised and you're looking for recourse.

You seem to believe that AML/KYC regulation exists to benefit customers or to prevent or recover from account compromises. It does not, and I have no idea why you would think it does. Something like a Yubikey or iris-scanning stations could help to prevent Coinbase account compromises, but AML/KYC regulations do not require or even encourage them, though perhaps someday they will.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#96

From the Coinbase website: https://www.coinbase.com/en-de/blog/protecting-our-customers... What they got - Name, address, phone, and email - Masked Social Security (last 4 digits only) - Masked bank‑account numbers and some bank account identifiers - Government‑ID images (e.g., driver’s license, passport) - Account data (balance snapshots and transaction history) Wow. Why does customer support staff have access to im…

[deleted]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#97
post #83
post #49

Earlier quoted context omitted.

Bank tellers are constantly surveilled by cameras, security guards, and several-times-daily cash counting, and it's still easy to find accounts of them having stolen significant amounts of money before getting caught. These are all from within the last year: Vannia Chatt: https://6abc.com/post/former-citizens-bank-teller-accused-st... Karen Farrell Tigler: https://www.irs.gov/compliance/criminal-investigation/former.…

Then shift liability and let the insurers take care of it. With a lot of this online stuff, no matter who gets your password or access to your account it’s you who has to take care of it. Whereas if the bank teller steals from the till it’s not your problem.

I suggest following the links I provided, which clearly demonstrate that the comment you posted in reply to them is false.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#98
post #24

Earlier quoted context omitted.

It's probably hard to keep call-center workers bribe-proof.

[flagged]

You mean like in the USA?

> ...bribed AT&T employees at a call center in Bothell, Washington, to "use their network credentials and exceed their authorized access to AT&T's computers to submit large numbers of fraudulent and unauthorized unlock requests on behalf of the conspiracy and to install malware and unauthorized hardware on AT&T's systems," according to the indictment.

https://abcnews.go.com/Politics/att-employees-bribed-1m-unlo...

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#99
post #35

Earlier quoted context omitted.

Yes, but I do think an organization like Coinbase or a cell phone carrier - which are extreme targets of fraud - have an obligation to recognize that their employees are targets and implement greater security measures than most organizations. Maybe Coinbase should even pay higher wages and use onshore customer service agents.

Well, it sounds like they do implement greater security measures than most organizations.

Doesn't matter when Coinbase still got exploited

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#100
post #24
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

It's probably hard to keep call-center workers bribe-proof.

Let me add to your statement. It is hard to keep call center workers bribe-proof WHEN they are paid peanuts AND they are working for a company that is in an extremely high risk business of managing crypto.
Post reply on HN