Coinbase reportedly knew about a significant data breach involving its outsourced customer support agents months before publicly disclosing the incident, according to Reuters. The breach, linked to an Indian contractor, compromised sensitive user data, enabling sophisticated social engineering scams that could cost the cryptocurrency exchange up to $400 million.
Delayed Disclosure Sparks Controversy
Coinbase was allegedly informed as early as January 2025 about a data breach involving its third-party contractor, TaskUs. Despite this, the cryptocurrency exchange did not publicly disclose the incident until a May 14 filing with the Securities and Exchange Commission (SEC). Coinbase stated it only became aware of the full scale of the operation on May 11, when it received a $20 million extortion demand.
The Outsourcing Vulnerability
The breach originated from an India-based TaskUs employee who was caught photographing work computer screens with a personal phone. This employee and an alleged accomplice were suspected of selling Coinbase user data to hackers for bribes. Coinbase had partnered with TaskUs to reduce labor costs by assigning customer support duties to offshore teams, where agents reportedly earned between $500 and $700 per month, making them vulnerable to criminal incentives. Coinbase has since severed ties with TaskUs and other involved overseas contractors.
Sophisticated Social Engineering Attacks
Hackers did not directly breach Coinbase's crypto wallets. Instead, they leveraged the stolen personal information to impersonate Coinbase employees, tricking users into moving their crypto assets through social engineering scams. Security researchers believe a loosely organized group known as “the Comm,” experienced in high-profile attacks, orchestrated the breach. Scammers used platforms like Telegram and Discord to coordinate operations and split proceeds, with some impersonators speaking fluent North American English to appear more credible.
Key Takeaways
-
Coinbase reportedly knew about the data breach months before public disclosure.
-
The breach involved outsourced customer support agents in India.
-
Hackers used stolen data for social engineering, not direct wallet breaches.
-
The incident could cost Coinbase up to $400 million.
-
Coinbase refused a $20 million extortion demand and is cooperating with law enforcement.
Financial Repercussions and Ongoing Investigations
The cybersecurity incident could cost Coinbase an estimated $180 million to $400 million in remediation and voluntary customer reimbursements. The company refused the $20 million extortion demand, fired compromised employees, and has since strengthened its internal controls. The U.S. Justice Department is reportedly investigating the data breach. Despite a shareholder lawsuit filed for delayed disclosure, Coinbase's stock has rebounded, bolstered by its recent inclusion in the S&P 500 index.
Sources
-
Coinbase knew of $400M data leak link in January, sources say, Cryptopolitan.
-
Report: Coinbase Learned of Data Breach in January, PYMNTS.com.
-
Coinbase Knew of Its Data Breach Months Before Disclosing: Reuters, Decrypt.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.