2025-05-15 (disclosed) · US · Coinbase
Coinbase support staff bribed to leak customer data, 2025
Disclosed by the affected organisation.
On 11 May 2025 Coinbase received an email from an unknown threat actor claiming to hold customer account data and internal documents, demanding money not to publish them. Coinbase said the actor appears to have paid multiple contractors or employees in support roles outside the US to collect data from internal systems. The data included names, contact details, masked Social Security and bank numbers, and government ID images, but no passwords, private keys or funds. Coinbase did not pay and estimated costs of $180 million to $400 million. BleepingComputer reported the demand was $20 million and that a former support agent was later arrested in India.
$180M (estimate; Low end of Coinbase's preliminary estimate of $180 million to $400 million in remediation costs and voluntary customer reimbursements.)
Timeline
- 2025-05-11 Coinbase receives the extortion email.
- 2025-05-15 Coinbase files a Form 8-K describing the incident, its refusal to pay, and a preliminary cost estimate.
Lessons
- Limit what support agents can see and export, and monitor for access without a business need, as Coinbase's monitoring had flagged.
- Apply the same insider-risk controls to outsourced support staff as to employees.
- Warn customers promptly when their data may be used for impersonation, because leaked support data feeds follow-on scams.
Scam types: Insider bribery and recruitment, Data theft extortion
Sources
- Coinbase Global: Form 8-K, Item 1.05 Material Cybersecurity Incident (May 2025) (Company disclosure, primary, accessed 2026-09-24)
- BleepingComputer: Former Coinbase support agent arrested for helping hackers (News report, secondary, accessed 2026-09-24)