2025-05-15 Coinbase Global, Inc. Cybersecurity Incident

Page last updated on May 15, 2025

Coinbase Global, Inc. initially disclosed a cybersecurity incident in an SEC 8-K filing on 2025-05-15 06:52:12 EDT.

Company Summary

Coinbase is a crypto exchange and wallet platform that allows merchants and consumers to buy, sell, and store digital currencies.

Incident Details

Material: Unknown
Is Breach: TRUE
Records Compromised: Unknown
Data Types Impacted: Driver License Number, Phone Number, Home address, Name

Compromised Date:
Detected Date: 2025-05-11
Disclosure Date: 2025-05-15
Contained Date:
Recovered Date:

Attack Goal: Unknown

Costs: No Costs Tracked (yet)

Filings

8-K filed on 2025-05-15

Coinbase Global, Inc. filed an 8-K at 2025-05-15 06:52:12 EDT
Accession Number: 0001679788-25-000094

Item 1.05 Material Cybersecurity Incidents.

On May 11, 2025, Coinbase, Inc., a subsidiary of Coinbase Global, Inc. (“Coinbase” or the “Company”), received an email communication from an unknown threat actor claiming to have obtained information about certain Coinbase customer accounts, as well as internal Coinbase documentation, including materials relating to customer-service and account-management systems. The communication demanded money in exchange for not publicly disclosing the information. The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities. These instances of such personnel accessing data without business need were independently detected by the Company’s security monitoring in the previous months. Upon discovery, the Company had immediately terminated the personnel involved and also implemented heightened fraud-monitoring protections and warned customers whose information was potentially accessed in order to prevent misuse of any compromised information. Since receipt of the email, the Company has assessed the email to be credible, and has concluded that these prior instances of improper data access were part of a single campaign (the “Incident”) that succeeded in taking data from internal systems. The Company has not paid the threat actor’s demand and is cooperating with law enforcement in the investigation of this Incident.

The Incident did not involve the compromise of passwords or private keys, and at no time were any of the targeted contractors or employees able to access customer funds. While the Company is still investigating the affected data, it included:


Company Information

NameCoinbase Global, Inc.
CIK0001679788
SIC DescriptionFinance Services
TickerCOIN - Nasdaq
Website
CategoryLarge accelerated filer
Fiscal Year EndDecember 30