• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Sunday, June 21, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Crypto

Inside the $20 Million Ransom Scheme: Coinbase’s Foreign Support Agents Bribed

by Anindya Paul
May 15, 2025
in Crypto
Reading Time: 4 mins read
0
Inside the $20 Million Ransom Scheme: Coinbase’s Foreign Support Agents Bribed

Source: CNBC

TwitterWhatsappLinkedin

Coinbase, the largest US cryptocurrency exchange, on May 15, 2025, reported that a sophisticated attack saw cybercriminals bribe foreign support agents to steal sensitive customer data and demand a $20 million ransom payment.
Though no passwords or private keys were taken, the breach exposed personal information—including names, contact information, government ID photos, masked bank account numbers, and the last four digits of Social Security numbers—of fewer than 1% of customers, laying the groundwork for spear-phishing scams. Coinbase puts estimates of remediation and reimbursement attempts at between $180 million to $400 million, but Coinbase has declined paying the ransom, opting instead for setting up a $20 million reward fund that will support efforts by law enforcers.

You might also like

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

How to Reduce Crypto Taxes Legally: Smart Strategies Every Cryptocurrency Investor Should Know

The Battle of the Stablecoins: A Comprehensive Guide to USDT vs USDC

Background of the Breach

On May 11, an anonymous email reached Coinbase from the threat actor reporting to possess in-house documentation as well as client account information and demanding $20 million to suppress public disclosure.
The data allegedly included internal customer service manuals and account management system documents in addition to personal user records. Coinbase first detected irregular access patterns months earlier through its security monitoring systems and immediately terminated the implicated staff, notifying affected customers and enhancing fraud protections.

The SEC Filing

In its May 14 filing with the U.S. Securities and Exchange Commission, Coinbase detailed the breach’s mechanics: multiple overseas contractors or employees in support roles were bribed to extract data beyond their business needs. The exchange stressed that no account credentials, private keys, or funds were accessed, but sensitive personal and financial details were compromised.

Modus Operandi: Bribed Support Agents

Rather than exploiting a software vulnerability, attackers paid support agents directly to abuse legitimate system access. These insiders collected data from internal customer support systems, supplying cybercriminals with the material needed to impersonate Coinbase staff and convince victims to transfer cryptocurrency. Insider threats such as these highlight the human factor as an important security vector.

Scope and Impact

Even though the breach impacted fewer than 1% of Coinbase’s user base, the affected records were extremely sensitive. Revealed information included:

  • Full names, addresses, phone numbers, and e-mail addresses
  • Masked bank account numbers and identifiers
  • Last four digits of Social Security numbers
  • Government-issued ID images
  • Account balance snapshots and transaction histories

Hacked customers have been cautioned against the possibility of phishing, with Coinbase agreeing to cover any who get taken in by such scams.In parallel, the exchange’s stock slid over 6% in morning trading on the breach’s announcement.

Financial Consequences and Refusal of Ransom

Coinbase estimates that cleanup expenses—such as system overhauls, legal fees, and customer refunds—will reach between $180 million and $400 million. In defiance of the threat in the ransom note, CEO Brian Armstrong went public to announce Coinbase would not pay the $20 million ransom, instead setting up an equivalent reward fund for tips leading to the arrest of the attackers. This is in line with broader industry best practice in discouraging cybercrime by paying ransom.

Response and Mitigation Measures

Coinbase outlined several measures taken subsequent to the breach within its official blog post:

  1. Termination of Rogue Employees: All such employees and contractors involved were fired.
  2. Customer Warnings: Affected users were warned and educated on how to prevent social engineering.
  3. Monitoring Upgrade: Anti-fraud controls were upgraded, with higher levels of authentication for high-risk transactions.
  4. Global Law Enforcement Partnership: Coinbase is cooperating closely with international authorities and has labeled suspicious wallet addresses to monitor illicit fund transactions.
  5. Reward Fund: There is a reward fund of $20 million for actionable information.

Wider Implications for Crypto Security

This incident is reflective of the increasing complexity of attacks against human weaknesses more than technical weaknesses. With growth in cryptocurrency exchanges, integrity of support channels and insider monitoring becomes overlord importance. Industry watchers point out investment scams in the crypto space totaled $3.96 billion in 2023, highlighting the magnitude of the problem. Improved KYC/AML processes, zero-trust access architecture, and ongoing employee screening can address insider threats.

Conclusion

By not paying the $20 million ransom and posting a reward for the capture of the perpetrators, Coinbase has made a strong stand against cyber extortion. Although remediation efforts weigh heavily on the balance sheet, the exchange’s prompt disclosure, cooperation with law enforcement, and efforts to improve internal controls are intended to rebuild user trust. As the first significant crypto company to join the S&P 500 next week, how Coinbase navigates this crisis will be watched closely as a benchmark for the sector’s resistance to human-focused cyber attacks.





Tags: Coinbasecryptocryptocurrency
Tweet56SendShare16
Previous Post

How to Upgrade to E-Chip Passport in India

Next Post

Volkswagen Gears Up for Electric Revolution with Next-Gen Golf GTI

Anindya Paul

Professional content creator with strong expertise in content writing, filmmaking and social media strategy. Skilled in digital storytelling, scriptwriting, video production, sound design and graphic design - crafting compelling narratives across platforms. Known for delivering high-quality, engaging content under tight deadlines. A collaborative team player with a sharp creative instinct, adaptability to evolving trends, and a focus on impactful, results-driven communication.

Recommended For You

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

by Anindya Paul
June 21, 2026
0
Bitcoin ETF

The issuance of Bitcoin exchange-traded funds (ETFs) has boosted investor confidence in cryptocurrency investments. Now, rather than physically owning and storing their investments through digital currency exchanges or...

Read more

How to Reduce Crypto Taxes Legally: Smart Strategies Every Cryptocurrency Investor Should Know

by Anindya Paul
June 21, 2026
0
Taxes

As time goes on, crypto-currency continues its evolution from a niche technological experiment to the newest global investment asset class worth trillions of dollars, with millions of investors...

Read more

The Battle of the Stablecoins: A Comprehensive Guide to USDT vs USDC

by Anindya Paul
June 19, 2026
0
USDC vs USDT

The world of cryptocurrency is well known for its extreme volatility; price can drop or increase by double digits within just a few minutes. For investors trying to...

Read more
Next Post
Volkswagen Gears Up for Electric Revolution with Next-Gen Golf GTI

Volkswagen Gears Up for Electric Revolution with Next-Gen Golf GTI

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?