Skip to content
cisonews.net

Incident · 8-K Item 1.05

Coinbase discloses extortion demand after insiders were paid to collect customer data

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Coinbase Global disclosed on May 15, 2025 that it had received an email on May 11 from an unknown threat actor claiming to hold customer account information and internal documents, with a demand for money. The crypto exchange said the data had been gathered by support contractors or employees outside the United States who were paid by the actor.

How Coinbase described the incident

Coinbase said its own monitoring had caught those instances of access in earlier months, and after the email it concluded they formed a single campaign. It did not pay the demand.

The data listed includes names, addresses, phone numbers and emails, masked Social Security and bank account numbers, government ID images, and balance snapshots and transaction history. Coinbase said passwords, private keys and customer funds were not accessed.

Cost estimate

Coinbase gave a preliminary range. It planned to reimburse eligible retail customers who had sent funds to the actor as a result.

Not stated

The filing does not give the number of customers affected or identify the actor.

Sources

  1. 2025-05-15 · ACoinbase Global, Inc., Form 8-K (SEC EDGAR), published May 15, 2025

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.