Coinbase Reports Customer Data Breach Via Bribed Support Agents, Offers Reimbursement

Coinbase today revealed that cyber criminals successfully bribed and recruited a group of what it described as rogue overseas support agents. These insiders allegedly abused their access to customer support systems to steal account data belonging to a small subset of Coinbase customers. The criminals reportedly used this data to facilitate social engineering attacks.
Coinbase stated that while customer data was accessed, no passwords, private keys, or customer funds were exposed. The company also confirmed that Coinbase Prime accounts remained untouched by the breach.
In response to the incident, Coinbase announced it will reimburse any customers who were tricked into sending funds to the attacker as a result of the breach. The company stated it is cooperating closely with law enforcement agencies to pursue the "harshest penalties possible" against those responsible. Coinbase also confirmed it will not pay a $20 million ransom demand it received. Instead, the exchange is establishing a $20 million reward fund for information that leads to the arrest and conviction of the criminals responsible for the attack.
The company detailed the types of customer data obtained by the criminals, which included names, addresses, phone numbers, and email addresses. They also gained access to masked Social Security numbers (last 4 digits only), masked bank account numbers and some bank account identifiers, images of government IDs (such as driver's licenses and passports), account data including balance snapshots and transaction history, and limited corporate data available to support agents (including documents, training material, and communications). Coinbase reiterated that login credentials, 2FA codes, private keys, the ability to move or access customer funds, access to Coinbase Prime accounts, and access to any Coinbase or Coinbase customer hot or cold wallets were not compromised.
Subscribe Now

