Coinbase says some employees’ information stolen by hackers • TechCrunch

Cryptocurrency exchange Coinbase has confirmed it was temporarily compromised by the same attackers who targeted Twilio, Cloudflare, DoorDash, and over 100 other organizations last year.

In a postmortem analysis of the incident published over the weekend, Coinbase said so-called “0ktapus” hackers stole the login credentials of one of its employees in an attempt to gain remote access to the company’s systems.

0ktapus is a hacking group that targets over 130 organizations in 2022, often spoofing Okta’s login pages, trying to steal the credentials of thousands of employees. According to a leaked Crowdstrike report reviewed by TechCrunch, the gang is now targeting several technology and video game companies.

For Coinbase, 0ktapus hackers sent spoofed SMS text messages to several employees on February 5, requiring them to urgently log in using the links provided to receive important messages. I told you something. One employee followed a phishing link and entered his credentials. In the next phase, the attackers attempted to log into her Coinbase’s internal systems using the stolen credentials, which failed as the access was protected by multi-factor authentication.

Approximately 20 minutes later, the attackers used voice phishing (“vishing”) to call an employee claiming to be an employee of the Coinbase IT team and trick the victim into logging into their workstation. instructed. This allowed the attacker to view employee information such as name, email address, and phone number.

“The attackers were able to view the dashboards of a handful of internal communication tools and access limited employee contact information,” Coinbase spokesperson Jaclyn Sales told TechCrunch. “Threat actors were able to view specific views of internal dashboards and access limited employee contact information through screen sharing.”

However, Coinbase said its security team responded quickly and prevented threat accessors from accessing customer data and funds. “Our security team was able to quickly detect anomalous activity and prevent other access to our internal systems and data,” added Sales.

Coinbase said it had no access to customer data, but the company’s chief information security officer, Jeff Langlhofer, is considering switching to hardware security keys for better access to accounts. It said it would encourage users to do so, but did not disclose whether it internally uses hardware keys that cannot be phished.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *