I'll guess the users had the same usernames and passwords that they've used for a hundred other sites, and one of those got breached at some point. Don't do that!
I'll guess the users had the same usernames and passwords that they've used for a hundred other sites, and one of those got breached at some point. Don't do that!
If they were certain this was PURELY a phishing campaign against their users, then they had no need to disclose to the government.
Their wording in their disclosure is very very carefully crafted to not deny a breach of their data - pending "conclusive" evidence.
They made a choice to disclose so that the gov't could never claim that they failed to disclose should Coinbase data appear on a darknet website.
And While they make an allusion to social media data collection - I was a target in June, and I absolutely had ZERO social media talking about using coinbase. There is NO WAY hackers could have deduced on social media that I was Coinbase user, nor gotten my cell phone number.
I am 90% confident that Coinbase WAS breached directly, allowing hackers to gain access to email and phone number for my account.
This disclosure is 100% CYA.
Did you ever use any other cryptocurrency website? If so, one of those could have been hacked in order for the hackers to get a list of users to target.
The thing that might have been hacked could have easily been a CRM or email marketing system - possibly even via some 3rd party supplier.
Obviously there was no hack of the Coinbase accounting system - for the reasons you mentioned.
password is 1FA.
SMS is 2FA (not a great one, but still). Coinbase failed at 2FA. 2FA is critically important; that's why it exists.
Not sure why you discount username and phone either. Each of these is an additional layer of security simply by being more information an attacker needs to collect and associate. Coinbase doesn't publish a list of usernames. And how would someone associate phone numbers back to them?
It’s unfortunate how much is out there.