Breach Teardown

Financial Services (Crypto)
2025

What Caused the Coinbase Insider Breach?

Nobody hacked Coinbase. Criminals paid people who already had access: outsourced customer support agents overseas, bribed to copy customer records out of internal support tools. The campaign surfaced only when the attackers themselves emailed a $20 million extortion demand. Coinbase refused to pay, disclosed the incident in an SEC filing, and put the same $20 million up as a bounty on the perpetrators.

By Vidyaa Ganesh, Founder, Identara

Scale
69,461 customers (per Maine AG filing); $180–400M estimated cost
Attack vector
Bribed overseas support contractors copying customer data
IAM domains implicated
Governance, Security
Domino controls hit
0 of 3

The Incident

What Happened

On May 11, 2025, Coinbase received an email demanding $20 million in exchange for not publishing stolen customer data. The company disclosed the incident in a Form 8-K days later, refused the demand, and instead announced a $20 million reward fund for information leading to the arrest and conviction of the attackers.

The mechanism was bribery rather than intrusion. Per Coinbase’s disclosure and subsequent reporting, threat actors paid overseas customer support agents, contractors working support queues from India, to pull customer records from the tools their jobs gave them access to. The stolen data included names, addresses, phone numbers, emails, government ID images, and masked bank account details. Passwords, private keys, and customer funds were not exposed. The agents involved were terminated.

Coinbase initially framed the exposure as less than 1% of monthly transacting users; a subsequent filing with the Maine Attorney General put the count at 69,461 customers. The company estimated remediation and reimbursement costs between $180 million and $400 million, and committed to reimbursing customers deceived into transferring funds through the social-engineering scams the stolen data now enables. Data that describes exactly who holds crypto, and where they live, is a targeting list.

Attack Chain

How the Attack Compounded

Each step below marks the AXIS control that failed at that point in the chain, where one applies. Steps without a control marker were outside the victim's direct span of control.

  1. Criminals identify outsourced support contractors with access to customer data and offer payment for copies of it.

    GOV-04

  2. Bribed agents use their legitimate support-tool access to look up and exfiltrate customer records. No credential is stolen; the sessions are real.

    SEC-04

  3. The copying runs for an extended period across multiple agents without the campaign’s scope being detected internally.

    SEC-03

  4. The aggregated dataset arrives back at Coinbase as leverage: a $20 million extortion email on May 11, 2025.

  5. Coinbase refuses, discloses, and posts a bounty; the stolen data fuels impersonation scams against the affected customers.

Control Mapping

The IAM Controls That Failed

Every failure point below corresponds to a control in the AXIS question bank, the same 3 controls a maturity assessment would have scored before this incident.

AXIS controls that failed in the Coinbase breach, with domain, capability, and how each failed
ControlDomainCapabilityHow it failed here
GOV-04GovernanceIAM Operating Model and SkillsCustomer data access was outsourced to overseas contractors without the operating model pricing in bribery as a threat. If a third party’s employees can read your customer records, their payroll is part of your attack surface, and vetting, rotation, and insider-risk controls belong in the contract.
SEC-04SecurityData Security Posture & Identity-to-Data Risk Mapping (DSPM)No one had bounded what a single support seat could reach. Masked bank details and ID images were still monetizable, and the blast radius of one bribed agent, multiplied across several, added up to tens of thousands of complete targeting profiles.
SEC-03SecurityUser Behavioral Analytics (UBA)Support accounts copying customer records beyond any queue’s legitimate need is post-authentication behavior, exactly what UBA exists to catch. The campaign’s full scope reached Coinbase through the attacker’s own extortion email rather than through internal analytics.

The Maturity Lesson

What Would Have Changed the Outcome

The Domino Effect

None of the three failed controls is a domino, and that is the uncomfortable lesson. Every front-door control the AXIS model treats as foundational, MFA, phishing resistance, recovery hardening, held perfectly, because the attacker never touched the front door. They purchased sessions that were legitimately issued to legitimately hired people. When authentication cannot fail because the insider is authenticated by design, what remains is blast radius, behavioral detection, and the governance of who gets that access in the first place.

The Maturity Level That Mattered

At level 2 or 3 on SEC-04, the data reachable from a support seat is a measured, bounded, masked-by-default quantity with export controls. At level 2 on SEC-03, volume and pattern anomalies on support tooling alert while the campaign is running, not after the ransom note. At level 2 or 3 on GOV-04, outsourced identity-adjacent functions carry contractual insider-risk controls: vetting, monitoring, and access proportional to the queue actually worked.

The assessment question this breach adds: price a bribe. What does one support seat see, what would it cost an attacker to buy that view, and would anything notice the copying? For platforms holding financial data, the honest answers are often uncomfortable.

Related Compliance Frameworks

The controls implicated in this breach carry citations in these frameworks within the AXIS bank:

Put a Number on It

What Would a Breach Like This Cost You?

The breach cost calculator turns a failure pattern like the one above into a dollar figure. Set your identity count, pick your industry, give an honest read of your IAM maturity, and see the annualized loss exposure it implies.

Run the Breach Cost Calculator

Sources

About This Analysis

This teardown is based exclusively on public disclosures, regulatory findings, and reporting cited above; it makes no claim of insider knowledge about the internal environment at Coinbase. Control mappings express how the publicly documented failure points correspond to capabilities in the AXIS methodology, for educational purposes. AXIS is not affiliated with Coinbase.

Would Your Program Have Caught This?

The 3 controls that failed here are questions in the AXIS assessment. Score your organization against them, and the rest of the bank, in about 20 minutes. No signup required to start.