Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Coinbase Insider Breach 2025: How Bribed Support Agents…
Breach analysis Incident: 15 May 2025

Coinbase Insider Breach 2025: How Bribed Support Agents Exposed 69,461 Customers

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 10 min read
On this page

In May 2025, Coinbase disclosed that criminals had paid a small number of overseas customer support agents to copy customer data out of its internal support tools, then demanded $20 million to keep quiet. No systems were hacked in the usual sense. The agents used access they had been legitimately given to do their jobs. Coinbase refused to pay, offered a $20 million reward instead, and estimated the cost of the incident at $180 million to $400 million. It is one of the clearest recent examples of an insider identity, rather than a stolen credential, being the attack path.

Key takeaways

  • Attackers paid "multiple contractors or employees working in support roles outside the United States" to collect customer information from internal Coinbase systems, according to Coinbase's SEC filing.
  • Data on 69,461 people was exposed, according to Coinbase's notice to the Maine Attorney General: names, contact details, the last four digits of Social Security numbers, masked bank details, government ID images, balances and transaction history.
  • No passwords, private keys or customer funds were taken. The data was used to impersonate Coinbase and trick customers into sending funds.
  • Coinbase received the extortion email on 11 May 2025, refused to pay, and estimated remediation and reimbursement costs at $180 million to $400 million. Reuters later reported Coinbase knew of data theft at its contractor TaskUs in January 2025.
  • Lessons: limit what each support identity can see, monitor bulk or unusual record access, and treat outsourced staff accounts as privileged third-party access.

At a glance

Organisation(s)Coinbase; outsourced support provider TaskUs (as reported by Reuters)
WhenData theft from 26 December 2024 (Maine Attorney General notice); extortion email 11 May 2025; disclosed 15 May 2025
AttackerUnnamed criminal group; a former support agent was arrested in Hyderabad, India, in December 2025
Entry pointBribery of customer support agents with legitimate access to internal support tools
Identities abusedHuman insider accounts of support agents and contractors, used within their granted permissions
Impact69,461 customers' personal and account data exposed; $20 million extortion demand refused; estimated costs of $180 million to $400 million
CategoryHuman identity (not listed as an NHI or AI agent breach)

What happened

On 15 May 2025, Coinbase published a blog post and filed a Form 8-K with the US Securities and Exchange Commission. It said that on 11 May 2025 it had received an email from an unknown threat actor claiming to hold information about certain Coinbase customer accounts and internal documents. In the filing, Coinbase said: "The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems". The attacker demanded $20 million.

In its blog post, Coinbase described the method plainly: "Criminals targeted our customer support agents overseas. They used cash offers to convince a small group of insiders to copy data in our customer support tools for less than 1% of Coinbase monthly transacting users." The stolen data included names, addresses, phone numbers and emails, the last four digits of Social Security numbers, masked bank account numbers and identifiers, government ID images such as driving licences and passports, account balances and transaction history, and limited corporate documents including training material.

The attackers did not get login credentials, 2FA codes, private keys or access to customer funds, and Coinbase Prime accounts were not affected. The purpose of the theft was social engineering: with a customer's balance, history and ID in hand, a caller posing as Coinbase can be very convincing. Coinbase said it would reimburse customers who had been tricked into sending funds to the attackers as a direct result of the incident.

Coinbase said the insiders "were fired on the spot and referred to U.S. and international law enforcement." It did not pay. Instead it set up a $20 million reward fund for information leading to the arrest and conviction of those responsible. In the 8-K it estimated remediation costs and voluntary reimbursements at "approximately $180 million to $400 million".

On 21 May 2025, Coinbase's notice to the Maine Attorney General put the number of affected people at 69,461 and gave the breach date as 26 December 2024, as reported by The Register and The Hacker News. In June 2025, Reuters reported, as summarised by Decrypt, that Coinbase had been made aware in January 2025 of a data breach involving its contractor TaskUs. TaskUs told Decrypt it had terminated two employees for illegal access, and said it "ceased all Coinbase operations in Indore, India, in early January 2025, impacting 226 teammates".

In December 2025, CEO Brian Armstrong said a former Coinbase customer support agent had been arrested in Hyderabad, India, according to TechNadu and Crowdfund Insider. Armstrong wrote: "We have zero tolerance for bad behavior and will continue to work with law enforcement to bring bad actors to justice," as reported by Cryptonews via Yahoo Finance.

Timeline

DateEvent
26 December 2024Breach date given in Coinbase's notice to the Maine Attorney General.
Early January 2025TaskUs ceases Coinbase operations in Indore, India, affecting 226 staff, according to TaskUs.
January 2025Coinbase made aware of the data breach involving TaskUs, according to Reuters.
11 May 2025Coinbase receives an extortion email demanding $20 million.
15 May 2025Coinbase discloses the incident in an SEC filing and blog post, refuses to pay and announces a $20 million reward fund.
21 May 2025Notice to the Maine Attorney General reports 69,461 affected individuals.
June 2025Reuters reports Coinbase knew of the TaskUs breach months before disclosure.
December 2025A former support agent is arrested in Hyderabad, India.

How it happened: the identity attack path

  1. Identifying who holds the data. The attackers targeted outsourced customer support agents, whose job gives them routine access to customer records in internal support tools.
  2. Buying the identity rather than stealing it. Cash offers turned a small number of legitimate users into insiders. No phishing, malware or password theft was needed.
  3. Using permitted access. The agents looked up and copied customer records through the same tools and accounts they used every day, so each individual query looked like normal work.
  4. Collecting at scale over time. Record by record, the insiders gathered data on tens of thousands of customers, including identity documents and balances.
  5. Weaponising the data. The attackers used the records to impersonate Coinbase and persuade customers to move funds, then tried to extort Coinbase itself for $20 million.

Impact

  • Customers: 69,461 people, described by Coinbase as less than 1% of monthly transacting users.
  • Data: personal details, partial Social Security numbers, masked bank details, government ID images, balances and transaction histories.
  • Financial: an estimated $180 million to $400 million in remediation costs and customer reimbursements, according to the 8-K.
  • Operational: termination of the insiders involved, closure of the affected TaskUs operation in Indore, and plans for a new US support hub.
  • Legal: an arrest in India in December 2025, with Coinbase working with law enforcement.

What this means for identity security

Coinbase is a reminder that an identity does not need to be compromised to be abused. The support agents' accounts were real, correctly authenticated and used within their granted permissions. MFA, phishing-resistant login and password hygiene all worked as designed and none of them mattered. The control gap was how much each identity could see, and whether anyone noticed when an account read far more records than its work required.

Outsourced support is a particular risk. Contractor identities often sit outside the company's own HR and governance processes, yet they carry access to highly sensitive customer data. Access should be scoped to the case in hand, revealed only when needed, and reviewed with the same rigour as employee access. Our Workforce Identity Security Guide covers these controls.

The same lesson applies directly to machine identities. A service account, API key or AI agent with broad read access to customer data is a standing insider that never tires. If it is misused, through a stolen token or a manipulated agent, it will also look like normal activity. Least privilege, just-in-time access and behavioural monitoring are the controls that catch both human and non-human insiders.

Recommendations

  • Scope support access to the case. Give agents access to a customer's record only when handling that customer's ticket, and mask sensitive fields such as ID images unless needed. See our Privileged Access Management Guide.
  • Monitor volume and pattern of record access. Alert when an agent views records unrelated to open tickets, or views far more records than peers.
  • Govern contractor identities as third-party access. Require outsourcing partners to meet your identity controls, share access logs and report suspected misuse immediately. Our IAM and IGA Basics guide covers access reviews.
  • Prepare customers for impersonation. After any data exposure, warn customers, add verification for flagged accounts and offer features such as withdrawal allow-listing.
  • Apply the same model to machine identities. Service accounts and AI agents that read customer data should have narrow scopes, owners and anomaly detection, as described in our NHI Lifecycle Management Guide.

Frequently asked questions

How was Coinbase breached in 2025?

Criminals paid a small number of overseas customer support contractors or employees to copy customer data from Coinbase's internal support tools. They then demanded $20 million from Coinbase, which refused to pay.

How many Coinbase customers were affected and what was taken?

69,461 people, according to Coinbase's notice to the Maine Attorney General. Data included names, contact details, partial Social Security numbers, masked bank details, government ID images, balances and transaction history, but not passwords, private keys or funds.

Is the Coinbase breach a non-human identity breach?

No, it was an insider breach using human support accounts. We include it because a legitimate identity with broad read access and weak monitoring is the same risk posed by over-privileged service accounts and AI agents.

Co-op Group breach · MGM Resorts breach · Human vs Non-Human Identity · Top 10 NHI Issues

How NHI Mgmt Group can help

Over-privileged identities cause breaches whether they belong to people or machines. Our NHI Foundation Level Training Course shows teams how to scope, monitor and govern service accounts, API keys, tokens, AI agents and other non-human identities so that legitimate access cannot quietly become a data breach.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org