Breach Teardown
What Caused the Coinbase Insider Breach?
Nobody hacked Coinbase. Criminals paid people who already had access: outsourced customer support agents overseas, bribed to copy customer records out of internal support tools. The campaign surfaced only when the attackers themselves emailed a $20 million extortion demand. Coinbase refused to pay, disclosed the incident in an SEC filing, and put the same $20 million up as a bounty on the perpetrators.
By Vidyaa Ganesh, Founder, Identara
- Scale
- 69,461 customers (per Maine AG filing); $180–400M estimated cost
- Attack vector
- Bribed overseas support contractors copying customer data
- IAM domains implicated
- Governance, Security
- Domino controls hit
- 0 of 3
The Incident
What Happened
On May 11, 2025, Coinbase received an email demanding $20 million in exchange for not publishing stolen customer data. The company disclosed the incident in a Form 8-K days later, refused the demand, and instead announced a $20 million reward fund for information leading to the arrest and conviction of the attackers.
The mechanism was bribery rather than intrusion. Per Coinbase’s disclosure and subsequent reporting, threat actors paid overseas customer support agents, contractors working support queues from India, to pull customer records from the tools their jobs gave them access to. The stolen data included names, addresses, phone numbers, emails, government ID images, and masked bank account details. Passwords, private keys, and customer funds were not exposed. The agents involved were terminated.
Coinbase initially framed the exposure as less than 1% of monthly transacting users; a subsequent filing with the Maine Attorney General put the count at 69,461 customers. The company estimated remediation and reimbursement costs between $180 million and $400 million, and committed to reimbursing customers deceived into transferring funds through the social-engineering scams the stolen data now enables. Data that describes exactly who holds crypto, and where they live, is a targeting list.
Attack Chain
How the Attack Compounded
Each step below marks the AXIS control that failed at that point in the chain, where one applies. Steps without a control marker were outside the victim's direct span of control.
Criminals identify outsourced support contractors with access to customer data and offer payment for copies of it.
GOV-04
Bribed agents use their legitimate support-tool access to look up and exfiltrate customer records. No credential is stolen; the sessions are real.
SEC-04
The copying runs for an extended period across multiple agents without the campaign’s scope being detected internally.
SEC-03
The aggregated dataset arrives back at Coinbase as leverage: a $20 million extortion email on May 11, 2025.
Coinbase refuses, discloses, and posts a bounty; the stolen data fuels impersonation scams against the affected customers.
Control Mapping
The IAM Controls That Failed
Every failure point below corresponds to a control in the AXIS question bank, the same 3 controls a maturity assessment would have scored before this incident.
| Control | Domain | Capability | How it failed here |
|---|---|---|---|
| GOV-04 | Governance | IAM Operating Model and Skills | Customer data access was outsourced to overseas contractors without the operating model pricing in bribery as a threat. If a third party’s employees can read your customer records, their payroll is part of your attack surface, and vetting, rotation, and insider-risk controls belong in the contract. |
| SEC-04 | Security | Data Security Posture & Identity-to-Data Risk Mapping (DSPM) | No one had bounded what a single support seat could reach. Masked bank details and ID images were still monetizable, and the blast radius of one bribed agent, multiplied across several, added up to tens of thousands of complete targeting profiles. |
| SEC-03 | Security | User Behavioral Analytics (UBA) | Support accounts copying customer records beyond any queue’s legitimate need is post-authentication behavior, exactly what UBA exists to catch. The campaign’s full scope reached Coinbase through the attacker’s own extortion email rather than through internal analytics. |
The Maturity Lesson
What Would Have Changed the Outcome
The Domino Effect
None of the three failed controls is a domino, and that is the uncomfortable lesson. Every front-door control the AXIS model treats as foundational, MFA, phishing resistance, recovery hardening, held perfectly, because the attacker never touched the front door. They purchased sessions that were legitimately issued to legitimately hired people. When authentication cannot fail because the insider is authenticated by design, what remains is blast radius, behavioral detection, and the governance of who gets that access in the first place.
The Maturity Level That Mattered
At level 2 or 3 on SEC-04, the data reachable from a support seat is a measured, bounded, masked-by-default quantity with export controls. At level 2 on SEC-03, volume and pattern anomalies on support tooling alert while the campaign is running, not after the ransom note. At level 2 or 3 on GOV-04, outsourced identity-adjacent functions carry contractual insider-risk controls: vetting, monitoring, and access proportional to the queue actually worked.
The assessment question this breach adds: price a bribe. What does one support seat see, what would it cost an attacker to buy that view, and would anything notice the copying? For platforms holding financial data, the honest answers are often uncomfortable.
Related Compliance Frameworks
The controls implicated in this breach carry citations in these frameworks within the AXIS bank:
Put a Number on It
What Would a Breach Like This Cost You?
The breach cost calculator turns a failure pattern like the one above into a dollar figure. Set your identity count, pick your industry, give an honest read of your IAM maturity, and see the annualized loss exposure it implies.
Run the Breach Cost CalculatorSources
About This Analysis
This teardown is based exclusively on public disclosures, regulatory findings, and reporting cited above; it makes no claim of insider knowledge about the internal environment at Coinbase. Control mappings express how the publicly documented failure points correspond to capabilities in the AXIS methodology, for educational purposes. AXIS is not affiliated with Coinbase.
More From the Breach Radar
What Caused the Charter Communications Breach?
Vishing for Entra credentials, then bulk Salesforce export
What Caused the Marks & Spencer Breach?
Impersonation call to an outsourced IT help desk
What Caused the Snowflake Customer Breaches?
Years-old infostealer credentials, no MFA on SaaS accounts
Would Your Program Have Caught This?
The 3 controls that failed here are questions in the AXIS assessment. Score your organization against them, and the rest of the bank, in about 20 minutes. No signup required to start.