Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Unknown hacker stole data from Coinbase employees

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,905
Reaction score
942
Points
212
Awards
2
  • trusted user
  • Rich User
Theft was obtained due to the naivety of one of the company's employees.

o4ngmygpscz74rqo9vatz3f9p0kecrca.jpg


The Coinbase cryptocurrency platform reported that an unknown attacker stole the credentials of one of the employees, trying to get remote access to the company's systems.

The cybercriminal received contact information from several Coinbase <TAG1 employees> names, phone numbers, email addresses (, but the funds and customer data are not affected.

Coinbase said the cybersecurity did not allow the hacker to gain direct access to the system and prevented any loss of funds or compromising customer information. Only a limited amount of data from the Coinbase corporate catalog was disclosed.

Coinbase shared the results of her investigation to help other companies determine the tactics, methods and procedures of the attacker ( TTPs ) and establish appropriate protection.

Attack details

The attack began on February 5, when an attacker sent several Coinbase SMS engineers urging them to enter their corporate accounts to read an important notice.

Most employees ignored the messages, but one of them fell into the – trick, he went over to the link to the phishing page and entered his credentials. Then the hacker tried to enter the internal systems of Coinbase using stolen credentials, but could not do this, since access was protected by multifactorial authentication ( MFA ).

After 20 minutes, the attacker called the company employee and introduced himself as an IT specialist for Coinbase. He convinced the victim to enter his workstation and perform some actions. The CSIRT Coinbase team discovered unusual activity within 10 minutes from the start of the attack and contacted the victim to find out about unusual actions from the account. Then the employee realized that there was a cyber attack, and stopped talking with an attacker.

Will Thomas from the Equinix Threat Analysis Center ( ETAC ) discovered several additional domains related to Coinbase and corresponding to the company description, which may have been used in the attack:

  • sso-cbhq [. ] com;
  • sso-cb [. ] com;
  • coinbase [. ] sso-cloud [. ] com.
It is worth noting that the course of action of the attacker is similar to what was observed during the 0ktapus phishing campaign last year.
 
Ad End 1 February 2024
Top