A Coinbase data breach filing with the Maine Attorney General finally gives us some more detail than Coinbase’s vague “less than 1% of monthly transacting users”. 69,461 people were affected, and Coinbase says the data breach occurred on December 26, 2024.

https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/f61fae18-f669-499e-9a87-f4d323d281f8.html

It took them almost five months between the incident and the incident disclosure, although the company has since admitted it knew customer support agents were suspiciously accessing customer data as far back as January.

#coinbase #crypto #cryptocurrency

Office of the Maine AG: Consumer Protection: Privacy, Identity Theft and Data Security Breaches

SEC requires material cybersecurity incidents be disclosed within four business days; state laws often have a 30-day disclosure deadline. It’s not clear if customers outside the US were affected; if so, other disclosure laws may apply.

#coinbase #crypto #cryptocurrency

Security researchers who have spent months trying to call Coinbase’s attention to serious issues at the company are disputing Coinbase’s claims about the timing of the breach. “Threat actors had ongoing access via multiple insiders over a prolonged period of time.”

@molly0xfff Coinbase is hiring an insider threat analyst, and I've applied for the position in the past (although I hate crypto and that's probably why I didn't get a callback lol)

*shrug* get fucked I guess lol

Coinbase hiring Insider Threat Analyst in United States | LinkedIn

Posted 5:03:39 PM. Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase…See this and similar jobs on LinkedIn.

@NosirrahSec @molly0xfff this might be one of those "keep a job listing alive so it looks like they care" but they never actually hire anybody and the job listing stays up forever, and people forget and move onto whatever the next calamity is

@Viss @molly0xfff I am absolutely convinced, unless someone can present data and facts to the contrary, that the vast majority of open reqs and jobs aren't actually getting hired.

They're putting up the appearance of hiring for key positions for optics and/or counter business intel. (I am not always this paranoid, but I don't think I'm alone in this theory either.)

@NosirrahSec @molly0xfff It would be a very good thing in this case for Coinbase to hire people who are deeeeeeply skeptical about cryptocurrency.

@kevinashworth @molly0xfff This is truly how I feel.

I could be wrong, but I believe my derision of crypto is an asset in this sort of position. I don't need to be obsessed with a thing to do my job passionately and effectively.

I'm passionate about my work, not their business. I don't think this is a bad thing.

@NosirrahSec @molly0xfff The fire department has recently had insider issues with pyromaniacs and arsonists on staff. We are looking into it. Actually we have a job opening to look into it. Must love fire to apply. Must have history of lighting things on fire to apply. Must dream of fire, and inexorably walking toward it, every night to apply.
@molly0xfff who forgot to feed the monkey?

@molly0xfff

Those dumpster fires can smolder for a long long time. 🔥 🤷‍♂️

@molly0xfff so wait... if that's the case then why do we seem to have to always. have to rely on company's maine filings?
@cryptadamist most companies aren’t public
@molly0xfff I would be surprised if NASDAQ didn't have disclosure requirements as well, maybe even pre-listing