Coinbase crypto heists, QR codes, and ransomware in the classroom
Feb 6, 2025
auto_awesome
Geoff White, a cybersecurity expert and author of "The Lazarus Heist," joins the discussion to unravel the mysteries behind a staggering $65 million lost from Coinbase. He critiques the cybersecurity failures of tools like PowerSchool, highlighting dangers for student data. The conversation also dives into the dark side of QR codes, revealing their exploitation in scams. With a mix of humor and insights, they emphasize the importance of vigilance in online safety amid rising cyber threats.
Coinbase's controversial advice to disable VPNs and ad blockers highlights a troubling focus on operational ease over essential user security.
The recent PowerSchool data breach exposes critical vulnerabilities in educational institutions, emphasizing the urgent need for transparency and robust protective measures.
The surge in QR code scams, particularly in public spaces, underscores the importance of public awareness and vigilance against fraudulent activities.
Deep dives
Ransomware Challenges and Communication Issues
A recent school data breach highlights the significant frustration caused by ineffective communication from ransomware operators. Many victims of such attacks are often left in the dark, as they struggle to contact support while their accounts become inaccessible. The ransomware problem is exacerbated by the lack of clear instructions and accountability from companies like PowerSchool, which recently suffered a data breach affecting numerous schools. The hackers typically don't maintain open lines of communication, forcing victims to navigate chaotic and confusing processes to regain access to their information.
Coinbase's Controversial Security Practices
Coinbase has come under scrutiny for advising its users to disable critical security measures, such as VPNs and ad blockers, due to policy that inaccurately associates these tools with suspicious activity. This stance has outraged many, especially in light of reports indicating that users are being locked out of their accounts without explanation or recourse. Analysts have pointed out that while such security measures are essential for protecting accounts, Coinbase's approach seems to prioritize operational ease over user security. This has led to increased financial risk for users who may find themselves unable to access their funds unexpectedly.
The Surge and Scams Involving QR Codes
The widespread adoption of QR codes has prompted a corresponding rise in scams associated with their use, particularly in public spaces like parking areas. Fraudsters have been known to place counterfeit QR codes on parking machines, tricking unsuspecting motorists into directing their payments to the scammer instead of the parking authority. Additionally, there are reports of scam packages arriving at people's homes, which then lead users to potentially malicious sites through deceptive QR codes. The rise of QR code scams emphasizes a need for increased public awareness and vigilance when interacting with these codes.
Evolution of Cryptocurrency Theft
Recent investigations into cryptocurrency theft have unveiled alarming tactics employed by scammers, reflecting the growing sophistication of online fraud. Some victims were misled by scammers impersonating Coinbase representatives, who used personal information to build trust before directing them to fraudulent actions. Reports indicate that substantial amounts, including hundreds of thousands of dollars, have been lost through these schemes, illustrating the risks associated with less regulated platforms. This highlights the essential need for users to be cautious and informed when engaging with cryptocurrency services.
PowerSchool Data Breach Response
The hack of PowerSchool, a software provider for educational institutions, has raised concerns about the sensitivity of the data at risk, ranging from student grades to personal information. Despite operating in a sector that is meant to protect minors, the breach has exposed significant vulnerabilities, and the full extent of the data stolen remains unclear. Many school administrators are taking it upon themselves to investigate and share insights on the breach due to a lack of information from PowerSchool, indicating a growing need for transparency in breach responses. This situation reflects the challenges facing educational data security and the urgent need for robust protective measures.
In episode 403 of "Smashing Security" we dive into the mystery of $65 million vanishing from Coinbase users faster than J-Lo slipped into Graham's DMs, Geoff gives a poor grade for PowerSchool's security, and Carole takes a curious look at QR codes.
All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White.
Warning: This podcast may contain nuts, adult themes, and rude language.
Tailscale – Tailscale is perfect for work or personal projects, making networking simple. Its free plan covers up to 100 devices and 3 users. Get started at tailscale.com and be up and running in less than 10 minutes!
Cortex Symphony 2025 - Ready to transform your cybersecurity? Register now to see the future of security innovation with exclusive insights, demos, and stories from pros.
SUPPORT THE SHOW:
Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!