Customer support agents of Coinbase cryptocurrency exchange sold stolen user data to hackers

📟 News

Date: 16/05/2025

Coinbase, Inc., a cryptocurrency exchange with over 100 million users, announced that some rogue customer support agents sold customer data to cybercriminals. The extortionists demanded a 20 million USD ransom for nondisclosure of the stolen information.

The company stated it won’t pay the ransom and instead will establish a 20 million USD reward fund for any information leading to the arrest and conviction of the criminals responsible for this attack

On May 11, 2025, hackers contacted Coinbase demanding a 20 million USD ransom. Otherwise they threatened to leak stolen customer account information and internal documents to the public domain.

According to Coinbase, the cybercriminals received the stolen data from contractors and rogue overseas support agents. The attackers paid insiders for access to company’s internal systems. Employees involved in this criminal operation have already been fired.

The hackers obtained personal data of some 1% of Coinbase customers (approximately 1 million people). However, the criminals were unable to steal customers’ private keys and passwords or gain access to Coinbase Prime accounts or victims’ hot and cold wallets.

The company has already filed a report with the United States Securities and Exchange Commission (SEC). According to this document, the stolen data include:

  • Name, address, phone, and email;
  • Masked Social Security (last 4 digits only);
  • Masked bank-account numbers and some bank account identifiers;
  • Government‑ID images (e.g., driver’s license, passport);
  • Account data (balance snapshots and transaction history); and 
  • Limited corporate data (including documents, training material, and communications available to support agents).

“Cyber criminals bribed and recruited a group of rogue overseas support agents to steal Coinbase customer data to facilitate social engineering attacks. These insiders abused their access to customer support systems to steal the account data for a small subset of customers. No passwords, private keys, or funds were exposed and Coinbase Prime accounts are untouched. We will reimburse customers who were tricked into sending funds to the attacker,” – Coinbase.

Coinbase didn’t disclose the number of customers affected by social engineering attacks and tricked into transferring money to the scammers. The company estimates the incident remediation costs and voluntary customer reimbursements at 180-400 million USD.

Coinbase intents to launch a new support hub in the U.S. and introduce stronger security controls and monitoring across all locations. The company has also increased its investment in insider-threat detection, automated response, and simulating similar security threats to find failure points in any internal system.

Company emphasizes that scammers posing as Coinbase employees may try to pressure you into moving your funds. Coinbase will never ask for the password, 2FA codes, or for you to transfer assets to a specific or new address, account, vault or wallet. It will never call or text you to give you a new seed phrase or wallet address to move your funds to.

“To the customers affected, we’re sorry for the worry and inconvenience this incident caused. We’ll keep owning issues when they arise and investing in world‑class defenses-because that’s how we protect our customers and keep the crypto economy safe for everyone. Coinbase will voluntarily reimburse retail customers who mistakenly sent funds to the scammer as a direct result of this incident prior to the date of this post, following a review to confirm the facts,” – Coinbase.

Related posts:
2025.03.12 — Mass exploitation of PHP-CGI vulnerability in attacks targeting Japanese companies

GreyNoise and Cisco Talos experts warn that hackers are actively exploiting CVE-2024-4577, a critical PHP-CGI vulnerability that was discovered and fixed in early June 2024. CVE-2024-457…

Full article →
2025.02.05 — Google patches Android zero-day vulnerability exploited by hackers

Google released the February set of patches for Android. In total, they fix 48 bugs, including a kernel zero-day vulnerability actively exploited by hackers. The zero-day's…

Full article →
2025.04.07 — Critical RCE vulnerability discovered in Apache Parquet

All versions of Apache Parquet up to and including 1.15.0 are affected by a critical remote code execution (RCE) vulnerability whose CVSS score is 10 out…

Full article →
2025.02.12 — 2.8 million IP addresses used to brute-force network devices

The Shadowserver Foundation warns of a massive web login brute-forcing attacks targeting nearly 2.8 million IP addresses per day. Unknown attackers are seeking…

Full article →
2025.01.22 — Fake Homebrew Infects macOS and Linux Machines with infostealer

Attackers use Google ads to disguise themselves as the Homebrew website and distribute malware targeting Mac and Linux systems and stealing logon credentials, browser data, and cryptocurrency wallets.…

Full article →
2025.02.01 — Critical RCE vulnerability fixed in Cacti

A critical vulnerability has been discovered in the open-source Cacti framework: it enables an authenticated attacker to remotely execute arbitrary code. Vulnerability's ID is CVE-2025-22604; its…

Full article →
2025.03.05 — Polish Space Agency disconnects its network due to hacker attack

Last weekend, the Polish Space Agency (POLSA) had to disconnect all of its systems from the Internet to localize an attack targeting its IT infrastructure. After discovering the intrusion,…

Full article →
2025.04.30 — Coinbase fixes 2FA bug that made customers panic

Cryptocurrency exchange Coinbase has fixed a bug in its Account Activity logs that caused customers to think their credentials were compromised. Earlier this month, BleepingComputer…

Full article →
2025.04.16 — Android devices will restart every three days to protect user data

Google introduces a new security feature for Android devices: locked and unused devices will be automatically restarted after three days of inactivity to return their memory to an…

Full article →
2025.02.08 — Hackers exploit RCE vulnerability in Microsoft Outlook

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Federal Civilian Executive Branch (FCEB) Agencies that they have to secure their systems from ongoing…

Full article →