Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users

A mandatory filing to the Maine Attorney General says 69,461 customers nationwide were affected and dates the breach back to last December.

Detecting Insider Threats

When Coinbase said last week that it had refused to pay a $20 million ransom tied to an insider leak, the company estimated the data theft touched “less than one percent” of monthly transacting users. A mandatory filing to the Maine Attorney General now pins the number at 69,461 customers nationwide and dates the breach back to last December.

According to the new disclosure form, a group of unidentified overseas customer-support contractors began siphoning data on December 26, 2024, but the breach didn’t come to light until Coinbase’s security team spotted suspicious activity on May 11 this year, the same day Coinbase received the extortion demand.

In the filing, Coinbase described the incident simply as “insider wrongdoing.”

The company said rogue contractors were bribed to supply names, postal and email addresses, phone numbers and the last four digits of Social Security numbers. Some records also included masked bank details plus images of driver’s licenses or passports, more than enough to mount convincing phishing scams.

Coinbase maintains that no funds were touched and that its Prime, hot-wallet and cold-storage systems were never at risk.  

Coinbase began mailing notification letters on May 30 and is offering affected users a year of IDX credit-monitoring and $1 million in identity-theft insurance.

The US cryptocurrency exchange said it will voluntarily reimburse retail customers who were duped into sending cryptocurrency to the scammers, once investigators verify each claim. 

It is also opening a new U.S. support hub, adding stronger insider-threat monitoring, and placing additional identity checks and scam-awareness prompts on high-risk withdrawals. 

Advertisement. Scroll to continue reading.

In an SEC filing last week, the company pegged the preliminary cost of remediation and reimbursements at between $180 million and $400 million.

Related: Coinbase Rejects $20M Extortion Demand After Insider Breach

Related: Cryptocurrency Stolen From Thousands of Coinbase Accounts

Related: Coinbase Hack Linked to Group Behind Twilio, Cloudflare Attacks

Related: Coinbase Pays $250K for ‘Market-Nuking’ Security Flaw

Related: Coinbase Users Face Ongoing Phishing Attacks

Written By

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a security community engagement expert who has built programs at major global brands, including Intel Corp., Bishop Fox and GReAT. Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Watch Now

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

People on the Move

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

Cybersecurity training and simulations provider SimSpace has appointed Peter Lee as Chief Executive Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.