In May 2025, Coinbase disclosed that criminals had paid a small number of overseas customer support agents to copy customer data out of its internal support tools, then demanded $20 million to keep quiet. No systems were hacked in the usual sense. The agents used access they had been legitimately given to do their jobs. Coinbase refused to pay, offered a $20 million reward instead, and estimated the cost of the incident at $180 million to $400 million. It is one of the clearest recent examples of an insider identity, rather than a stolen credential, being the attack path.
Key takeaways
- Attackers paid "multiple contractors or employees working in support roles outside the United States" to collect customer information from internal Coinbase systems, according to Coinbase's SEC filing.
- Data on 69,461 people was exposed, according to Coinbase's notice to the Maine Attorney General: names, contact details, the last four digits of Social Security numbers, masked bank details, government ID images, balances and transaction history.
- No passwords, private keys or customer funds were taken. The data was used to impersonate Coinbase and trick customers into sending funds.
- Coinbase received the extortion email on 11 May 2025, refused to pay, and estimated remediation and reimbursement costs at $180 million to $400 million. Reuters later reported Coinbase knew of data theft at its contractor TaskUs in January 2025.
- Lessons: limit what each support identity can see, monitor bulk or unusual record access, and treat outsourced staff accounts as privileged third-party access.
At a glance
| Organisation(s) | Coinbase; outsourced support provider TaskUs (as reported by Reuters) |
|---|---|
| When | Data theft from 26 December 2024 (Maine Attorney General notice); extortion email 11 May 2025; disclosed 15 May 2025 |
| Attacker | Unnamed criminal group; a former support agent was arrested in Hyderabad, India, in December 2025 |
| Entry point | Bribery of customer support agents with legitimate access to internal support tools |
| Identities abused | Human insider accounts of support agents and contractors, used within their granted permissions |
| Impact | 69,461 customers' personal and account data exposed; $20 million extortion demand refused; estimated costs of $180 million to $400 million |
| Category | Human identity (not listed as an NHI or AI agent breach) |
What happened
On 15 May 2025, Coinbase published a blog post and filed a Form 8-K with the US Securities and Exchange Commission. It said that on 11 May 2025 it had received an email from an unknown threat actor claiming to hold information about certain Coinbase customer accounts and internal documents. In the filing, Coinbase said: "The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems". The attacker demanded $20 million.
In its blog post, Coinbase described the method plainly: "Criminals targeted our customer support agents overseas. They used cash offers to convince a small group of insiders to copy data in our customer support tools for less than 1% of Coinbase monthly transacting users." The stolen data included names, addresses, phone numbers and emails, the last four digits of Social Security numbers, masked bank account numbers and identifiers, government ID images such as driving licences and passports, account balances and transaction history, and limited corporate documents including training material.
The attackers did not get login credentials, 2FA codes, private keys or access to customer funds, and Coinbase Prime accounts were not affected. The purpose of the theft was social engineering: with a customer's balance, history and ID in hand, a caller posing as Coinbase can be very convincing. Coinbase said it would reimburse customers who had been tricked into sending funds to the attackers as a direct result of the incident.
Coinbase said the insiders "were fired on the spot and referred to U.S. and international law enforcement." It did not pay. Instead it set up a $20 million reward fund for information leading to the arrest and conviction of those responsible. In the 8-K it estimated remediation costs and voluntary reimbursements at "approximately $180 million to $400 million".
On 21 May 2025, Coinbase's notice to the Maine Attorney General put the number of affected people at 69,461 and gave the breach date as 26 December 2024, as reported by The Register and The Hacker News. In June 2025, Reuters reported, as summarised by Decrypt, that Coinbase had been made aware in January 2025 of a data breach involving its contractor TaskUs. TaskUs told Decrypt it had terminated two employees for illegal access, and said it "ceased all Coinbase operations in Indore, India, in early January 2025, impacting 226 teammates".
In December 2025, CEO Brian Armstrong said a former Coinbase customer support agent had been arrested in Hyderabad, India, according to TechNadu and Crowdfund Insider. Armstrong wrote: "We have zero tolerance for bad behavior and will continue to work with law enforcement to bring bad actors to justice," as reported by Cryptonews via Yahoo Finance.
Timeline
| Date | Event |
|---|---|
| 26 December 2024 | Breach date given in Coinbase's notice to the Maine Attorney General. |
| Early January 2025 | TaskUs ceases Coinbase operations in Indore, India, affecting 226 staff, according to TaskUs. |
| January 2025 | Coinbase made aware of the data breach involving TaskUs, according to Reuters. |
| 11 May 2025 | Coinbase receives an extortion email demanding $20 million. |
| 15 May 2025 | Coinbase discloses the incident in an SEC filing and blog post, refuses to pay and announces a $20 million reward fund. |
| 21 May 2025 | Notice to the Maine Attorney General reports 69,461 affected individuals. |
| June 2025 | Reuters reports Coinbase knew of the TaskUs breach months before disclosure. |
| December 2025 | A former support agent is arrested in Hyderabad, India. |
How it happened: the identity attack path
- Identifying who holds the data. The attackers targeted outsourced customer support agents, whose job gives them routine access to customer records in internal support tools.
- Buying the identity rather than stealing it. Cash offers turned a small number of legitimate users into insiders. No phishing, malware or password theft was needed.
- Using permitted access. The agents looked up and copied customer records through the same tools and accounts they used every day, so each individual query looked like normal work.
- Collecting at scale over time. Record by record, the insiders gathered data on tens of thousands of customers, including identity documents and balances.
- Weaponising the data. The attackers used the records to impersonate Coinbase and persuade customers to move funds, then tried to extort Coinbase itself for $20 million.
Impact
- Customers: 69,461 people, described by Coinbase as less than 1% of monthly transacting users.
- Data: personal details, partial Social Security numbers, masked bank details, government ID images, balances and transaction histories.
- Financial: an estimated $180 million to $400 million in remediation costs and customer reimbursements, according to the 8-K.
- Operational: termination of the insiders involved, closure of the affected TaskUs operation in Indore, and plans for a new US support hub.
- Legal: an arrest in India in December 2025, with Coinbase working with law enforcement.
What this means for identity security
Coinbase is a reminder that an identity does not need to be compromised to be abused. The support agents' accounts were real, correctly authenticated and used within their granted permissions. MFA, phishing-resistant login and password hygiene all worked as designed and none of them mattered. The control gap was how much each identity could see, and whether anyone noticed when an account read far more records than its work required.
Outsourced support is a particular risk. Contractor identities often sit outside the company's own HR and governance processes, yet they carry access to highly sensitive customer data. Access should be scoped to the case in hand, revealed only when needed, and reviewed with the same rigour as employee access. Our Workforce Identity Security Guide covers these controls.
The same lesson applies directly to machine identities. A service account, API key or AI agent with broad read access to customer data is a standing insider that never tires. If it is misused, through a stolen token or a manipulated agent, it will also look like normal activity. Least privilege, just-in-time access and behavioural monitoring are the controls that catch both human and non-human insiders.
Recommendations
- Scope support access to the case. Give agents access to a customer's record only when handling that customer's ticket, and mask sensitive fields such as ID images unless needed. See our Privileged Access Management Guide.
- Monitor volume and pattern of record access. Alert when an agent views records unrelated to open tickets, or views far more records than peers.
- Govern contractor identities as third-party access. Require outsourcing partners to meet your identity controls, share access logs and report suspected misuse immediately. Our IAM and IGA Basics guide covers access reviews.
- Prepare customers for impersonation. After any data exposure, warn customers, add verification for flagged accounts and offer features such as withdrawal allow-listing.
- Apply the same model to machine identities. Service accounts and AI agents that read customer data should have narrow scopes, owners and anomaly detection, as described in our NHI Lifecycle Management Guide.
Frequently asked questions
How was Coinbase breached in 2025?
Criminals paid a small number of overseas customer support contractors or employees to copy customer data from Coinbase's internal support tools. They then demanded $20 million from Coinbase, which refused to pay.
How many Coinbase customers were affected and what was taken?
69,461 people, according to Coinbase's notice to the Maine Attorney General. Data included names, contact details, partial Social Security numbers, masked bank details, government ID images, balances and transaction history, but not passwords, private keys or funds.
Is the Coinbase breach a non-human identity breach?
No, it was an insider breach using human support accounts. We include it because a legitimate identity with broad read access and weak monitoring is the same risk posed by over-privileged service accounts and AI agents.
Related NHI Mgmt Group resources
Co-op Group breach · MGM Resorts breach · Human vs Non-Human Identity · Top 10 NHI Issues
How NHI Mgmt Group can help
Over-privileged identities cause breaches whether they belong to people or machines. Our NHI Foundation Level Training Course shows teams how to scope, monitor and govern service accounts, API keys, tokens, AI agents and other non-human identities so that legitimate access cannot quietly become a data breach.
References
- Coinbase: Protecting Our Customers, Standing Up to Extortionists (15 May 2025)
- US Securities and Exchange Commission: Coinbase Global, Inc. Form 8-K (May 2025)
- The Register: Coinbase confirms insiders handed over data of 70K users (21 May 2025)
- The Hacker News: Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails (15 May 2025)
- Decrypt: Coinbase Knew of Its Data Breach Months Before Disclosing: Reuters (3 June 2025)
- TechNadu: Former Coinbase Support Agent Arrested in India Over Insider Data Breach (30 December 2025)
- Crowdfund Insider: Coinbase Data Breach Leads To Arrest In India Amid Ongoing Crackdown (28 December 2025)
- Yahoo Finance (Cryptonews): India Arrests Former Coinbase Support Agent Over Data Breach: Armstrong (28 December 2025)