news.volyx.in

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom (cnbc.com)

422 points by gpi · 442 days ago · 499 comments on HN

Article summary

Coinbase reported that hackers bribed overseas support agents to steal customer data, including names, addresses, and Social Security numbers. The company estimated the incident may cost up to $400 million to fix. Coinbase received a $20 million ransom demand but refused to pay, instead establishing a $20 million reward fund for information leading to the arrest and conviction of the hackers. The company has cooperated with law enforcement and enhanced its fraud monitoring protections.

Main themes

  • data breach
  • ransom demand
  • security measures
  • customer protection
  • offshoring risks
  • corporate responsibility

What commenters say

  • Paying the ransom demand would not guarantee the return of stolen data and could encourage future attacks.
  • Coinbase's decision not to pay the ransom is a good response to the hackers.
  • The company's security measures were inadequate, and it is responsible for the data breach.
  • Offshoring customer support to low-wage countries increases the risk of bribery and data breaches.
  • Implementing greater security measures, such as better vetting of employees and onshore customer service, could help prevent similar incidents.
  • Coinbase's announcement was worded in a way that shifted focus from apologizing for the breach to congratulating themselves on standing up to extortionists.
  • The damage from the data breach is already done, and paying the ransom would not limit the harm.
  • Coinbase should prioritize reimbursing and protecting affected customers over establishing a reward fund for the hackers' capture.