Data Breaches

Coinbase Rejects $20M Ransom After Rogue Contractors Bribed to Leak Customer Data

Coinbase said a group of rogue contractors were bribed to pull customer data from internal systems, leading to a $20 million ransom demand.

Cryptocurrency heist

Coinbase on Thursday laid out the full scope of a security breach first disclosed to the SEC, confirming that a group of rogue contractors were bribed to pull customer data from internal systems and then demand a $20 million payoff. 

Coinbase chief executive Brian Armstrong said the cryptocurrency exchange “won’t fund criminal activity” and is instead setting up a $20 million reward fund for information that leads to the arrest and conviction of the extortionists.

In a filing with the Security and Exchanges Commission, Coinbase said criminals made contact May 11 claiming to possess data on “less than one percent” of monthly transacting users along with internal customer-support documentation. 

“They used cash offers to convince a small group of insiders to copy data in our customer support tools for less than 1% of Coinbase monthly transacting users. Their aim was to gather a customer list they could contact while pretending to be Coinbase, tricking people into handing over their crypto,” Armstrong explained.

“They then tried to extort Coinbase for $20 million to cover this up. We said no,” the Coinbase CEO added.

The attackers had paid rogue contractors in non-U.S. support centers to copy information they were already authorized to view, an abuse the company said its monitoring tools had detected months earlier. 

Advertisement. Scroll to continue reading.

Armstrong said those workers were fired at the time, but only now has Coinbase linked the incidents to a single campaign.

According to the disclosure, the stolen cache includes customer names, addresses, phone numbers, email addresses, the last four digits of Social Security numbers, and masked bank-account numbers and related identifiers.

Coinbase confirmed the hijacked data included images of driver’s licenses or passports, balance snapshots, transaction histories, and limited corporate training materials. 

The attackers did not obtain login credentials, two-factor-authentication codes, private keys, or any ability to move customer funds, the company said, noting that Coinbase Prime accounts, hot wallets, and cold wallets were untouched.

Coinbase said it will voluntarily reimburse retail customers who were duped into sending cryptocurrency to the scammers, once investigators verify each claim. It is also opening a new U.S. support hub, adding stronger insider-threat monitoring, and placing additional identity checks and scam-awareness prompts on high-risk withdrawals. 

In its SEC filing the company pegged the preliminary cost of remediation and reimbursements at between $180 million and $400 million.

Related: Cryptocurrency Stolen From Thousands of Coinbase Accounts

Related: Coinbase Hack Linked to Group Behind Twilio, Cloudflare Attacks

Related: Coinbase Pays $250K for ‘Market-Nuking’ Security Flaw

Related: Coinbase Users Face Ongoing Phishing Attacks

Related Content

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Cybercrime

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.

Cybercrime

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.

Cybercrime

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Data Breaches

FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.

Data Breaches

The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

Ransomware

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version