Close Menu
The CISO Brief
  • Home
  • Cyberattacks
    • Ransomware
    • Cybercrime
    • Data Breach
  • Emerging Tech
  • Threat Intelligence
    • Vulnerabilities
    • Cyber Risk
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Why Compromised Credentials Are the #1 Attack Vector in 2024

June 15, 2025

Anubis Ransomware Unleashes File-Wiping Fury

June 14, 2025

WestJet Faces Cyberattack Disrupting Operations

June 14, 2025
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cyberattacks
    • Ransomware
    • Cybercrime
    • Data Breach
  • Emerging Tech
  • Threat Intelligence
    • Vulnerabilities
    • Cyber Risk
  • Expert Insights
  • Careers and Learning
  • Compliance
The CISO Brief
Home » Hack could cost Coinbase up to $400M: filing
Vulnerabilities

Hack could cost Coinbase up to $400M: filing

Staff WriterBy Staff WriterMay 17, 2025Updated:May 17, 2025No Comments3 Mins Read3 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


Coinbase doesn’t plan on bending to a $20 million ransom demand from hackers who coaxed customer information out of international support agents, the company said Thursday.

Instead, Coinbase is offering a $20 million reward for information leading to the arrest and conviction of these hackers, who bribed “weak links” found on the cryptocurrency exchange company’s customer support team to access 1% of customers’ information, CEO Brian Armstrong said on social media site X.

“Our support tools have limited access to customer information. There [were] no passwords or private keys or funds accessed as part of this, but customer support agents do have access to personal information like name, date of birth, address, etc.,” Armstrong said. “Attackers still want access to this information because it allows them to conduct social engineering attacks, where they can call our customers, impersonating Coinbase customer support and try to trick them into sending their funds to the attacker.”

Social engineering attacks, which bypass technical defenses by manipulating people into giving up private information, account for 70% to 90% of cyberattacks, according to cybersecurity software firm Secureframe. Phishing and smishing – phishing’s SMS cousin – are common instances of social engineering attacks.

Through a few “bad apples,” Coinbase’s leaked information included names, addresses, phone numbers and email addresses; masked Social Security numbers; masked bank account numbers; driver’s license and passport photos; and balance and transaction histories, according to a company blog post.

The incident – which Coinbase learned of from an attacker email Sunday demanding ransom – could cost the exchange up to $400 million, according to a securities filing, between remediating security issues and reimbursing customers.

As a result, the company will move some of its customer support operations, including by opening a new support hub in the U.S. 

Coinbase terminated all personnel involved and implemented heightened fraud-monitoring protections, according to the filing, and notified customers whose information was potentially accessed.

“For these would-be extortionists or anyone seeking to harm Coinbase customers, know that we will prosecute you and bring you to justice,” Armstrong said in his video on X.

The cyber incident comes in what is otherwise a big week for Coinbase. It announced Wednesday that it will be joining the S&P 500 on May 19 – the first crypto exchange to do so – and The New York Times reported Thursday that the exchange is under investigation by the Securities and Exchange Commission for allegedly misstating verified users.

“This is a hold-over investigation from the prior administration about a metric we stopped reporting two and a half years ago, which was fully disclosed to the public,” Chief Legal Officer Paul Grewal said in an emailed statement to Banking Dive. “We explained that the verified users metric includes anyone who verified their email address or phone number with us, so it may overstate the number of unique customers.”

“We also disclosed – and continue to disclose – the more relevant metric of ‘monthly transacting users’ – the number of people who use our platform in a given month. While we strongly believe this investigation should not continue, we remain committed to working with the SEC to bring this matter to a close,” Grewal said.

Coinbase’s first-quarter filing indicates the company has 9.7 million MTUs. By that metric, Sunday’s cyber incident affected up to 97,000 people.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAustralian Infrastructure Faces ‘Acute’ Foreign Threats
Next Article Weekly Cybertech Roundup: Highlights of the Week
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

UNFI Struggles to Recover from Cyberattack Setback

June 13, 2025

Exploiting SimpleHelp: A Security Wake-Up Call for Utility Billing Users

June 13, 2025

Cyberattacks Surge to the Forefront of Global Business Worries

June 13, 2025
Leave A Reply Cancel Reply

Latest Posts

Anubis Ransomware Unleashes File-Wiping Fury

June 14, 20250 Views

WestJet Faces Cyberattack Disrupting Operations

June 14, 20250 Views

Outage Unrelated to Security: Your Data Remains Safe!

June 13, 20250 Views

Google Links Major Cloud Outage to API Management Glitch

June 13, 20250 Views
Don't Miss

Big Risks for Malicious Code, Vulns

By Staff WriterFebruary 14, 2025

Attackers are finding more and more ways to post malicious projects to Hugging Face and…

North Korea’s Kimsuky Attacks Rivals’ Trusted Platforms

February 19, 2025

Deepwatch Acquires Dassana to Boost Cyber Resilience With AI

February 18, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Why Compromised Credentials Are the #1 Attack Vector in 2024

June 15, 2025

Anubis Ransomware Unleashes File-Wiping Fury

June 14, 2025

WestJet Faces Cyberattack Disrupting Operations

June 14, 2025
Most Popular

Attackers lodge backdoors into Ivanti Connect Secure devices

February 15, 20255 Views

VanHelsing Ransomware Builder Leaked: New Threat Emerges!

May 20, 20254 Views

SonicWall SMA 1000 series appliances left exposed on the internet

February 14, 20254 Views
© 2025 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.