Coinbase suffers data breach, gets extorted (but won’t pay)


Cryptocurrency exchange platform Coinbase has suffered a breach, which resulted in attackers acquiring customers’ data that can help them mount social engineering attacks, the company confirmed today by filing a report with the US Securities and Exchange Commission (SEC).

Coinbase data breach

The attack did not involve the compromise of company systems or networks. Instead, the data was accessed by a group of malicious support agents.

How did the attack happen?

According to the US-based company, criminals bribed some customer support agents to copy customer data and share it with them.

“Their aim was to gather a customer list they could contact while pretending to be Coinbase—tricking people into handing over their crypto. They then tried to extort Coinbase for $20 million to cover this up,” Coinbase shared, and declared that they did not and will not pay the ransom.

“Instead of paying the $20 million ransom, we’re establishing a $20 million reward fund for information leading to the arrest and conviction of the attackers.”

The compromised data

On May 11, 2025, Coinbase received an email from the attackers, asking for money in exchange for not publicly disclosing the compromised information.

“The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities,” company said in the SEC filing.

Ostensibly, Coinbase’s own security monitoring flagged instances of personnel accessing data without business need in the months before. They terminated those agents and warned customers whose information was potentially accessed.

The rogue agents got their hands on customers’ name, address, phone number, emails address, the last 4 digitls of their Social Security number, masked bank account numbers and some bank account identifiers, images of government-issued IDs, and some account data (transaction history, snapshots of customers’ Coinbase account balance).

They did not have access to customers’ login credentials and 2-factor authentication codes, private keys, hot or cold wallets, Coinbase Prime accounts, nor did they have the ability to move or access customer funds.

Coinbase’s reaction

Coinbase is the one of the world’s leading crypto exchanges and it and its 100+ million customers are often targeted by attackers adept at social engineering.

Unfortunately, the compromised data is enough to allow the scammers to credibly impersonate Coinbase support agents and try to trick or pressure customers into moving their funds.

Thus, the company has advised them to be on the lookout for scammy emails, texts or phonecalls, and reiterated that a legitimate Coinbase employee would never ask them to share their password, 2FA codes, or give them new seed phrase or wallet address to move their funds to.

“Coinbase will voluntarily reimburse retail customers who mistakenly sent funds to the scammer as a direct result of this incident prior to the date of this post, following a review to confirm the facts,” the company said.

Aside from setting up the reward fund for information on the criminals, Coinbase is working on tracking stolen funds and recovering them.

They have also put in place additional measures to detect insider threats, increased security controls and monitoring across all company locations, and have added protections to the accounts of the “less than 1% of monthly transacting users” whose data has been compromised.

“Flagged accounts now require additional ID checks on large withdrawals and include mandatory scam‑awareness prompts. As we monitor high risk transactions, you may experience delays,” the company stated, and added that they will be pressing criminal charges against the fired employees.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews



In the trailer for Mission: Impossible — The Final Reckoning, Tom Cruise as Ethan Hunt asks someone to trust him one last time. Judging by the first reactions on social media, Cruise is now asking the audience to trust him that he still delivered an action spectacle.

The social media embargo lifted for Mission: Impossible — The Final Reckoning on May 12. The initial reactions are mixed, which comes as a surprise considering how much praise the last few entries have received.

Erik Davis of Fandango and Rotten Tomatoes said Cruise takes The Final Reckoning to the next level. “It’s the biggest, wildest, and most consequential Mission movie yet,” Davis wrote on X.

Good Day’s Chicago Jake Hamilton called the plane sequence “one of cinema’s greatest stunts.” Hamilton wrote, “Mission: Impossible — The Final Reckoning is a love letter to fans who just rewatched the entire series.”

MISSION: IMPOSSIBLE – THE FINAL RECKONING is a love letter to fans who just rewatched the entire series.

It ties the entire series together as one story rather than 8 entries.

First time I’ve cried in the series.

Plane sequence is one of cinema’s greatest stunts.

I loved it. pic.twitter.com/3HxWtsY3HY

— Jake Hamilton (@JakesTakes) May 13, 2025

Indiewire’s David Ehrlich had a more negative reaction, calling it “dull and dysfunctional.” Despite praising the set pieces, Ehrlich was ultimately disappointed by The Final Reckoning, calling it a “massive heartbreaker.”

Mission: Impossible — The Final Reckoning is dull and dysfunctional in a way i didn’t think this franchise was capable of. setpieces are obviously incredible, but as someone so supportive of Cruise’s crusade to save the movies and whatnot this was a massive heartbreaker.

— david ehrlich (@davidehrlich) May 13, 2025

Griffin Schiller compared Final Reckoning to The Rise of Skywalker, saying it “plays like an egregious franchise greatest hits.”

While not as bad as TROS, FINAL RECKONING is undoubtedly cut from the same cloth. Plagued by insecurity, MISSION: IMPOSSIBLE 8 plays like an egregious franchise greatest hits. Scenes have no beginning or end, it’s scatterbrained nonsense – a constant flow of exposition &… pic.twitter.com/uCOclGGAsl

— Griffin Schiller (@griffschiller) May 13, 2025

Mission: Impossible is the gold standard for action franchises, so it’s disappointing to read about the mixed reactions. Cruise’s action sequences, including the death-defying plane stunt, will certainly be a highlight. However, the conflicting reception is not ideal, especially for a franchise that might have to disappear for the foreseeable future before Cruise returns or another actor steps in as the new lead.

Cruise headlines The Final Reckoning as Ethan Hun, the IMF agent who must race to find the Entity and destroy it before it gets into the wrong hands. The ensemble includes Hayley Atwell, Ving Rhames, Simon Pegg, Esai Morales, Pom Klementieff, Henry Czerny, Mariela Garriga, Holt McCallany, Janet McTeer, Nick Offerman, Hannah Waddingham, Tramell Tillman, Shea Whigham, Greg Tarzan Davis, Charles Parnell, Mark Gatiss, Rolf Saxon, Lucy Tulugarjuk and Angela Bassett.

Christopher McQuarrie directs from a screenplay he co-wrote with Erik Jendresen.

Mission: Impossible — The Final Reckoning opens in theaters on May 23.








Source link