How the Coinbase data breach happened: bribed support agents and a $20 million demand
Nobody hacked Coinbase's servers to steal data on about 69,000 customers. Criminals paid a handful of the company's own overseas support agents to look it up for them.[1][4] This case file covers how the insider scheme worked, how Coinbase answered a $20 million extortion demand, what it cost, and the one control that would have made the bribes worth far less.
What happened
Coinbase, the crypto exchange, used outsourced support staff abroad to help customers with account problems. According to a later class action lawsuit, one agent at the outsourcing firm TaskUs in India began pulling Coinbase customer records for outsiders around September 2024, and the problem widened from there.[6] In January 2025 TaskUs says it caught 2 employees who had illegally accessed a client's information and reported them. It then shut down its Coinbase support work in Indore, affecting 226 staff.[5]
On May 11, 2025, Coinbase received an email from an unknown attacker. It claimed to hold customer account data and internal documents and demanded $20 million to keep quiet.[1][3] On May 15 Coinbase filed a report with the Securities and Exchange Commission, published a blog post refusing to pay, and began notifying affected customers.[1][2]
Instead of paying, the company offered a $20 million reward for information leading to the arrest and conviction of the people behind it.[2] Filings with state attorneys general later put the number of affected customers at 69,461.[4]
How it worked
This was an inside job paid from the outside. The SEC filing says an unknown threat actor paid multiple contractors and employees in support roles outside the US to collect data from Coinbase systems they could already reach as part of their jobs.[1] No password was cracked and no firewall was breached. The agents simply looked up records and handed them over. Reporting on the case described one agent photographing her work screen with a personal phone.[5] The class action alleges records were sold for about $200 each.[6]
What the agents could see is the heart of the case. The stolen data included names, addresses, phone numbers and emails, the last 4 digits of Social Security numbers, masked bank account numbers, images of driver's licenses and passports, account balances and transaction history.[1][2] Passwords, two-factor codes and private keys were not taken, and the agents could not move customer funds.[2]
That did not make the data harmless. Knowing someone's balance, address and recent trades is exactly what a scammer needs to call a customer, pose as Coinbase support and talk them into moving their coins to a "safe" wallet the scammer controls. That is why Coinbase promised to reimburse retail customers tricked into sending funds as a direct result of the incident.[2]
How it was caught
Coinbase says its security monitoring had already flagged support staff pulling data with no business need in the months before the demand arrived, and those people were fired.[1] The extortion email is what turned a quiet personnel problem into a public disclosure. Coinbase was later criticized after Reuters reported it had been told of the leak in January 2025, months before it went public, and a shareholder lawsuit followed.[5]
In December 2025, CEO Brian Armstrong announced that police in Hyderabad, India had arrested a former Coinbase customer service agent linked to the breach, and said more arrests would follow.[8]
What it cost
In its May filing Coinbase estimated $180 million to $400 million in costs for remediation and voluntary customer reimbursements.[1] In its second-quarter 2025 results it reported $307 million in expenses tied to the incident.[7] The affected group was under 1% of the roughly 9.7 million customers who traded in a typical month, a small share with a very large bill.[3]
Coinbase also announced a new US-based support hub, extra ID checks for large withdrawals from affected accounts and more spending on insider threat detection.[2] TaskUs now faces a class action lawsuit over its role.[6]
The missing control
The missing control: least-privilege access for support staff. Frontline agents could open full customer profiles, including ID photos, bank details and balances, far beyond what most support tickets need.
Detection worked here, but only after the data had left. Tighter limits would have made each bribe worth much less. If an agent can see only the fields a ticket requires, sensitive items such as ID images stay masked unless a supervisor approves, and lookups are tied to an open ticket for that customer, then a corrupt agent can leak only a trickle. Bulk browsing of unrelated accounts would also stand out much sooner. The attackers were buying access, and access is the thing a business controls.
What to do in your business
- List what each role can see. Open your customer system as a front-desk or support user and write down every field visible. Hide anything that role does not need to do the job.
- Mask the crown jewels by default. Show only the last digits of account and ID numbers, and require a second approval to view full ID images or bank details.
- Tie lookups to a reason. Where your software allows it, require a ticket, order or call record before a staff member can open a customer's file, and review who opened records with no matching request.
- Hold outsourcers to the same rules. Put access limits, logging and prompt breach reporting in every contract with a call center, bookkeeper or IT provider that touches customer data.
- Warn customers before scammers call. Tell customers plainly that you will never ask them to move money or share codes, so a caller who knows their details still gets a no.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- The Ubiquiti hack was an inside job: how a senior developer extorted his employer
- How one trader brought down Barings Bank: account 88888
- How a Twitter employee sold user data to Saudi Arabia for a watch and cash
- The Tesla insider bribe plot: the $1 million offer an employee reported
- How a security training company hired a North Korean fake IT worker
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. SEC: Coinbase Global Form 8-K, May 14, 2025
- Coinbase: Protecting our customers, standing up to extortionists
- The Record: Coinbase says hackers bribed staff to steal customer data, offers $20 million reward
- The Register: Coinbase confirms insiders handed over data of 70K users
- Decrypt: Coinbase knew of data breach months before disclosure (citing Reuters)
- Infosecurity Magazine: TaskUs employees behind Coinbase breach, US court filing alleges
- The Block: Coinbase reports data theft cost $307 million in Q2
- The Block: Coinbase CEO announces first arrest in India over insider data breach