Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

1–10 of 287 posts

Re: Coinbase Breach Notification

#2
Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure).

Edit: California, not Canada. My bad.

Re: Coinbase Breach Notification

#4
> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you.

I see 2 conflicting claims here:

> While we are not able to determine conclusively how these third parties gained > access to this information

"these" being username, pw, phone number etc. And then:

> We have not found any evidence that these third parties obtained this information from Coinbase itself.

You're technically correct but the first claim undermines the second one to me.

Re: Coinbase Breach Notification

#5
What can be said that has not already?

It's like people saying, "I don't like the bank with their ridiculous paperwork so I will use a loan shark instead, he doesn't need paperwork"

Then the loan shark disappears/beats you up/asks for loads of interest etc. and you still want to complain to the police.

Most people hate regulators but they are there for a reason. What certifications does coinbase have to hold your millions of dollars of virtual currency?

Re: Coinbase Breach Notification

#6
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

*Californian government.

Re: Coinbase Breach Notification

#7
post #6
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

*Californian government.

[deleted]

Re: Coinbase Breach Notification

#8
In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox. While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks ... Even with the information described above, additional authentication is required in order to access your Coinbase account. However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.

We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost

Re: Coinbase Breach Notification

#10
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> had to perform a "SIM swap" type attack on the users.

source? I kind of doubt that's something coinbase would call a flaw in their system?

Post reply on HN