Throwaway account for obvious reasons. I have had my identity stolen twice, in both cases with the intent to steal access to accounts I use in connection with my business. Two relevant pieces of information: my employer pays for my phone, and I get reimbursements by submitting the PDF bill via Expensify. My employer is also a bitcoin company, and occasionally I have to buy bitcoin (a few hundred dollars worth) to top up our service’s wallet for paying transaction fees.
When the second incident happened a few months ago I had just come back from a long International trip. I work in the bitcoin industry and know not to keep coins on exchanges, but I also know not to travel through customs with >$10k or with bitcoin private keys on my person. So I had 8btc, about $30k at the time, loaded on my personal account on a certain exchange, in case (1) I needed emergency funds and was locked out of my bank account for ordinary fraud prevention snafu reasons; and/or (2) I needed to top-up company accounts again. It turns out I did need to do the latter.
Immediately on coming home I filed my expense reports for reimbursement. Expensify, as far as I can tell, does not allow a way to opt out of SmartScan” from the mobile app. In any case I thought this was some harmless excuse for the CTO to have a machine learning project. Little did I know. This report included both my phone bill for the months prior, and the bitcoin transfer, a print-out from the logged in view of my account on the exchange.
Very shortly thereafter (days?) my phone was remotely SIM-ported to another device. I got extremely lucky in that I was using the phone at the very moment it happened, and saw it go from full bars to “No service” while sitting in my chair. I knew what was going on because this was the 2nd time it had happened to me. I ran do the coffee shop down the street to get wifi, and found I could no longer login to my email account. Yup, hack in process. Attacker used SMS authentication on my cell phone to reset the password on the email.
Lacking a phone, I rushed to the nearest retail store for my carrier, and after a short conversation I had my phone service back. I had to answer some questions to regain my account, questions like “from which country did you recently make international calls, and to whom?” On getting full bars back on the device, I sat down and did a recovery of my email account, using the same process as the attacker now that I had regained control of my phone. I opened the “sessions” tab and logged out the other device, an IP I didn’t recognize from the other side of the country. 42 minutes elapsed from loss of phone service to account recovery.
Now here’s where things took a scary twist: I go back to my inbox, and as I watch I see an “Account reset requested” email from the company that provides 2FA services for my preferred bitcoin exchange. Inside the email is a link to confirm the request and receive a code to download the credentials (they save them to the cloud?! wtf!?) to a new device. Right below that in the inbox: “Password reset” from that bitcoin exchange, containing a clicked link (I presume, the email was read) that takes you their new-password form that requires 2FA. The 2FA input box has a link next to it that loads the 2FA app reset procedure that authenticates by email & SMS and then sends the root seed information.
As quickly as I could get back home to my secure, non-travel laptop with a read-only USB boot drive, I logged into my exchange account using the old credentials, and swept the $30k of coins (thankfully still there) to my cold storage. The paranoia was because at the time I didn’t know whether it was malware or what that had leaked enough information for the attacker to impersonate me. I spent the next few days reinstalling and virus scanning, resetting all passwords, and redoing my operational security to make sure this doesn’t happen again. (General advice: draw a flowchart showing what information you need to have to reset each of your credentials. Make sure it progresses from most trusted to least trusted, don’t have any loops, and keep your most trusted root credentials/passwords offline. Dollar-bill sized paper is excellent. Maybe an envelope with a $100 bill. Unless you are richer than I am, your instincts will make you secure that.)
But here’s what bugged me. Unlike the time before this happened to me, this was a hyper focused targeted attack. Even a few seconds later and those coins would have been gone. Unlike the last time the attacker didn’t try to get into anything else — just went straight to the exchange, and that particular exchange. Additionally, as this had happened before I had instructed my telephone company in no uncertain terms to never, ever do a SIM reset without authorization in person using the best available methods.
Now it comes together, and I am pissed about it. I was able to recover my phone by answering questions about its usage only I would know… like who I called, and what country I called from. Only those are listed right on the phone bill! A form of ID might be required, but seriously what do they check on that? The name and photo? Faked. The home address? Printed on the bill! And why did they go straight to the exchange? Because I submitted a screenshot of a transaction that included exactly how much hard currency I was stupid enough to leave on it. My email was easily googable (the perils of having a truly unique name). Those mechanical Turk contractors who processed my receipts had access to it all.
So Expensify, you’ve got some answering to do. I pretty clear now I came within seconds of losing a rather large portion of my nest egg and deal with identify theft resolution because you shared confidential and private information with hourly (minute-ly?) sub-contractors not subject to background review, oversight, or background checks, and certainly not subject to your commercial and third-party confidentiality agreements. You may try to argue they were, but any competent judge would reject the proposition that a worker being paid mere cents to fill out a text field from a picture as quickly as possible before moving onto another task from another company, was able to read, understand, before seek independent legal advice on your agreement before clicking through, assuming it got showed to them at all.
“Oh but your company signed our terms of service” you say. Yes, well the relevant stuff is in the privacy policy, referenced by the terms of service. Let’s look at that: Section 5, Disclosure of Personal Data. You say you only allow third parties (and further transfers) to access personal data in compliance with this same privacy policy, which forbids usage, like identity theft, not necessary to performance of services.
Maybe this is what slipped past your legal team: RECEIPTS ARE PERSONAL AND COMPANY CONFIDENTIAL INFORMATION. That phone bill? Personally identifiable information. That receipt for hosting expenses? That’s our raw cost, and company confidential information. Privacy of this information matters, and even if you tried to indemnify yourself in your policy, which you failed to do, you still run afoul of user protection laws, even in the company-friendly USA. There are stiff fines and civil liabilities for not taking sufficient safeguards to secure protected user data.
You damn lucky that I didn’t lose that $30k, or you better believe I’d be lawyering up. But I sincerely doubt I was the only one targeted either, and some probably successfully. Can you cover that liability? Are your investors ready to take that risk? I almost lost $30k. What about the assistant to the oil company CEO who expenses a coffee down the road from the headquarters of the competing oil company the rumor mill says they’re going to acquire? What happens when insider trading props up the price killing the deal, causing the company to enter bankruptcy and the shareholders file suit for the leak? You ready to carry that liability?
This is inexcusable. This is reckless. This is mismanagement of confidential company and personal data exposes you to knowable liabilities and reflects monumentally poor decision making. You’d better take steps NOW to disable this “feature”, issue apologies, provide tools for users to know what receipts were “SmartScanned” by your totally and completely not automated or in-house service.
And you’d best do that before you start facing lawsuits.