Coinbase has implemented a requirement for in-person training for employees following an incident where North Korean IT workers attempted to approach the company as remote freelancers for cyber extortion.
Reasons for New Security Measures
Coinbase faced security challenges when North Korean IT workers were identified attempting to infiltrate its structure through a decentralized staffing approach. As a result, a new policy was enacted requiring U.S. citizenship and in-person onboarding for certain roles.
Financial Implications and Coinbase's Response
Projected remediation costs for the incident are between $180 and $400 million. Coinbase refused to pay a $20 million ransom demand and instead offered a similar bounty for information about the perpetrators. The incident exposed user data from 69,461 accounts, but no major digital assets were affected.
Future Industry Changes and Regulatory Role
This incident underscores the need for enhanced cybersecurity measures in the industry. Regulators and industry leaders may call for tightening controls and improving vetting and hiring processes to prevent similar breaches in the future. Historically, North Korean groups such as Lazarus have used similar methods to target exchanges.
In response to these threats, Coinbase is implementing new security measures that could significantly change the industry's approach to cybersecurity and internal risks.