Coinbase disclosed in May 2025 that cybercriminals had bribed and recruited a group of overseas customer support agents to extract customer data and enable subsequent social engineering against account holders. Approximately 69,500 people — around 1% of its customer base — were affected. The company offered a $20 million reward for information leading to the identification of those responsible.
Every Control Worked
There is no vulnerability in this file. No unpatched device, no exposed endpoint, no credential stuffed from a prior breach. Authorised employees, using their own legitimate access, performed lookups they were entitled to perform.
The security model was not defeated. It was rented. Technical controls of any strength are indifferent to the motive of a person who is genuinely authorised — the point this desk filed at 26-0719, where three quarters of insider incidents involved nobody being malicious. This is the quarter that were.
The Economics Are The Finding
A support agent in a low-cost outsourcing centre earns an amount an attacker can beat with a single payment. The company operating the platform is worth billions. Between those two facts sits a support function selected for cost.
That gap is not a Coinbase-specific failure — it is the structure of every outsourced support operation in this corpus, from 26-0208 to 25-0512. The distinctive feature here is that the data being looked up was directly convertible: an account holder’s identity, contact details and holdings are the inputs to a targeted impersonation, and the target holds bearer assets.
Which Is Why The Data Mattered More Than The Volume
69,500 people is small against almost everything else in this database. It produced a nine-figure cost estimate because each record was not an identity-theft risk in the abstract; it was a qualified lead for a fraud with an irreversible settlement mechanism.
Once a transfer confirms, there is no chargeback, no issuing bank and no reversal. The remediation frameworks this corpus keeps criticising at least assume a transaction that can be disputed.
On The Reward
A $20 million bounty for information rather than a payment to the extortionists is an unusual move and, on this desk’s reading, a defensible one: it directs money at identification rather than at suppression, which is the transaction shown to be worthless at 25-0507.
Compiled from public reporting of company disclosures, listed below. The characterisation of recruitment is the company’s as reported. No individual has been identified in the material we reviewed. Corrections: corrections@forensicpost.com.