U.S. cryptocurrency exchange Coinbase was made aware of a customer data leak at one of its outsourcing companies four months before a breach that is set to cost it $400 million, a Reuters report citing six sources has said. In one incident, an employee of the outsourcing company Taskus was caught taking photos of her work computer, and a report was made to Coinbase.
According to five anonymous former employees quoted in the report, the unnamed female employee and an accomplice are believed to have passed on customer information to hackers in return for bribes. An investigation into the incident, which happened in the city of Indore, was launched. Shortly afterward, 200 Taskus employees were abruptly terminated, prompting allegations of unfair dismissal by the affected employees.
However, despite this incident, Coinbase only publicly acknowledged the breach in May after hackers in possession of sensitive user data attempted to extort $20 million from the exchange. As reported by Bitcoin.com News and other outlets, Coinbase publicly acknowledged the breach May 15. It claimed then that attackers only targeted internal customer support systems and accessed personal information belonging to fewer than 1% of monthly transacting users.
Coinbase’s confirmation of the breach came against the background of rising incidents in which wealthy crypto holders are being targeted by armed criminals. As some kidnapping incidents have demonstrated, criminals behind these abductions often seem to possess detailed information on users, including the size of their holdings. Some observers believe the cost of this breach significantly exceeds the monetary value.
Although it became aware that contractors had illegally obtained user “data in previous months” Coinbase only took action after the bribery attempt. The exchange added that it has also “cut ties with the TaskUs personnel involved and other overseas agents, and tightened controls.” For its part, Taskus said the two employees were let go in January.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。