Case file · COINBASE 2025

How the Coinbase data breach happened: bribed support agents and a $20 million demand

Published 2026-09-29 · 5 min read · Missing control: Least-privilege limits on support data

Nobody hacked Coinbase's servers to steal data on about 69,000 customers. Criminals paid a handful of the company's own overseas support agents to look it up for them.[1][4] This case file covers how the insider scheme worked, how Coinbase answered a $20 million extortion demand, what it cost, and the one control that would have made the bribes worth far less.

What happened

Coinbase, the crypto exchange, used outsourced support staff abroad to help customers with account problems. According to a later class action lawsuit, one agent at the outsourcing firm TaskUs in India began pulling Coinbase customer records for outsiders around September 2024, and the problem widened from there.[6] In January 2025 TaskUs says it caught 2 employees who had illegally accessed a client's information and reported them. It then shut down its Coinbase support work in Indore, affecting 226 staff.[5]

On May 11, 2025, Coinbase received an email from an unknown attacker. It claimed to hold customer account data and internal documents and demanded $20 million to keep quiet.[1][3] On May 15 Coinbase filed a report with the Securities and Exchange Commission, published a blog post refusing to pay, and began notifying affected customers.[1][2]

Instead of paying, the company offered a $20 million reward for information leading to the arrest and conviction of the people behind it.[2] Filings with state attorneys general later put the number of affected customers at 69,461.[4]

How it worked

This was an inside job paid from the outside. The SEC filing says an unknown threat actor paid multiple contractors and employees in support roles outside the US to collect data from Coinbase systems they could already reach as part of their jobs.[1] No password was cracked and no firewall was breached. The agents simply looked up records and handed them over. Reporting on the case described one agent photographing her work screen with a personal phone.[5] The class action alleges records were sold for about $200 each.[6]

What the agents could see is the heart of the case. The stolen data included names, addresses, phone numbers and emails, the last 4 digits of Social Security numbers, masked bank account numbers, images of driver's licenses and passports, account balances and transaction history.[1][2] Passwords, two-factor codes and private keys were not taken, and the agents could not move customer funds.[2]

That did not make the data harmless. Knowing someone's balance, address and recent trades is exactly what a scammer needs to call a customer, pose as Coinbase support and talk them into moving their coins to a "safe" wallet the scammer controls. That is why Coinbase promised to reimburse retail customers tricked into sending funds as a direct result of the incident.[2]

How it was caught

Coinbase says its security monitoring had already flagged support staff pulling data with no business need in the months before the demand arrived, and those people were fired.[1] The extortion email is what turned a quiet personnel problem into a public disclosure. Coinbase was later criticized after Reuters reported it had been told of the leak in January 2025, months before it went public, and a shareholder lawsuit followed.[5]

In December 2025, CEO Brian Armstrong announced that police in Hyderabad, India had arrested a former Coinbase customer service agent linked to the breach, and said more arrests would follow.[8]

What it cost

In its May filing Coinbase estimated $180 million to $400 million in costs for remediation and voluntary customer reimbursements.[1] In its second-quarter 2025 results it reported $307 million in expenses tied to the incident.[7] The affected group was under 1% of the roughly 9.7 million customers who traded in a typical month, a small share with a very large bill.[3]

Coinbase also announced a new US-based support hub, extra ID checks for large withdrawals from affected accounts and more spending on insider threat detection.[2] TaskUs now faces a class action lawsuit over its role.[6]

The missing control

The missing control: least-privilege access for support staff. Frontline agents could open full customer profiles, including ID photos, bank details and balances, far beyond what most support tickets need.

Detection worked here, but only after the data had left. Tighter limits would have made each bribe worth much less. If an agent can see only the fields a ticket requires, sensitive items such as ID images stay masked unless a supervisor approves, and lookups are tied to an open ticket for that customer, then a corrupt agent can leak only a trickle. Bulk browsing of unrelated accounts would also stand out much sooner. The attackers were buying access, and access is the thing a business controls.

What to do in your business

Watch the case
Coinbase Was Robbed Through Its Own Support DeskDrops 2026-10-20
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More insider risk cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. U.S. SEC: Coinbase Global Form 8-K, May 14, 2025
  2. Coinbase: Protecting our customers, standing up to extortionists
  3. The Record: Coinbase says hackers bribed staff to steal customer data, offers $20 million reward
  4. The Register: Coinbase confirms insiders handed over data of 70K users
  5. Decrypt: Coinbase knew of data breach months before disclosure (citing Reuters)
  6. Infosecurity Magazine: TaskUs employees behind Coinbase breach, US court filing alleges
  7. The Block: Coinbase reports data theft cost $307 million in Q2
  8. The Block: Coinbase CEO announces first arrest in India over insider data breach