Coinbase disclosed a data breach after rogue contractors stole customer data and demanded a $20M ransom.
The breach, affecting under 1% of users, was reported to the SEC after a ransom demand was received on May 11, 2025.
The unauthorized access was detected in previous months, leading to termination of involved personnel and implementation of heightened fraud-monitoring measures.
Compromised data includes contact details, partial SSNs and bank info, ID images, account history, and limited internal documents but did not expose passwords, private keys, or customer funds.