Desk live·
ForensicPost
Cloud/Insider/File 25-0514

Coinbase Says Attackers Bribed Overseas Support Agents for Customer Data

Coinbase disclosed that attackers bribed and recruited overseas support agents to extract customer data. Around 69,500 people were affected — about 1% of its customers.

Constructed geometry · not a chart of case data
TargetCoinbase
ActorUnattributed
D. Kennedy12 min readConfidence: high3 sources reviewed

Coinbase disclosed in May 2025 that cybercriminals had bribed and recruited a group of overseas customer support agents to extract customer data and enable subsequent social engineering against account holders. Approximately 69,500 people — around 1% of its customer base — were affected. The company offered a $20 million reward for information leading to the identification of those responsible.

Every Control Worked

There is no vulnerability in this file. No unpatched device, no exposed endpoint, no credential stuffed from a prior breach. Authorised employees, using their own legitimate access, performed lookups they were entitled to perform.

The security model was not defeated. It was rented. Technical controls of any strength are indifferent to the motive of a person who is genuinely authorised — the point this desk filed at 26-0719, where three quarters of insider incidents involved nobody being malicious. This is the quarter that were.

The Economics Are The Finding

A support agent in a low-cost outsourcing centre earns an amount an attacker can beat with a single payment. The company operating the platform is worth billions. Between those two facts sits a support function selected for cost.

That gap is not a Coinbase-specific failure — it is the structure of every outsourced support operation in this corpus, from 26-0208 to 25-0512. The distinctive feature here is that the data being looked up was directly convertible: an account holder’s identity, contact details and holdings are the inputs to a targeted impersonation, and the target holds bearer assets.

Which Is Why The Data Mattered More Than The Volume

69,500 people is small against almost everything else in this database. It produced a nine-figure cost estimate because each record was not an identity-theft risk in the abstract; it was a qualified lead for a fraud with an irreversible settlement mechanism.

Once a transfer confirms, there is no chargeback, no issuing bank and no reversal. The remediation frameworks this corpus keeps criticising at least assume a transaction that can be disputed.

On The Reward

A $20 million bounty for information rather than a payment to the extortionists is an unusual move and, on this desk’s reading, a defensible one: it directs money at identification rather than at suppression, which is the transaction shown to be worthless at 25-0507.

How we reported this

Compiled from public reporting of company disclosures, listed below. The characterisation of recruitment is the company’s as reported. No individual has been identified in the material we reviewed. Corrections: corrections@forensicpost.com.

Sources
  1. Top 10 cyber-attacks of 2025Infosecurity Magazine
  2. From Bybit to Coinbase: 2025’s biggest crypto hacks and breachesYahoo Finance
  3. Crypto hacks 2025: full list of scams, exchange exploits and DeFi vulnerabilitiesCCN
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary