A support contractor at Coinbase improperly accessed customer data affecting around 30 people, with access dated to December 2025 and screenshots surfacing in early 2026.
Thirty is the smallest affected population in our database this year. It is here because the failure class is one the rest of the database cannot describe.
Every Control Assumed This Person Belonged
Authentication succeeded because the credentials were genuinely theirs. Authorisation succeeded because support staff need customer records to do support. Monitoring saw a support contractor viewing customer records, which is the expected behaviour of a support contractor.
There is no technical signal distinguishing a legitimate lookup from an illegitimate one. The difference is intent, and intent is not a field.
Detection Has To Be Behavioural And After The Fact
What does work is comparative: lookups without a corresponding ticket, access to accounts outside an assigned queue, volume outside peer norms, or repeated interest in high-value accounts. All of it is statistical, all of it produces false positives against real people, and all of it operates after the access.
It also requires an organisation to accept that it is monitoring its own staff and contractors, which is a decision with cultural and legal weight rather than a configuration change.
Small Numbers, Concentrated Harm
Thirty customers of a cryptocurrency exchange is not thirty ordinary records. Account balances, transaction history and identity documents held together are directly actionable for targeted social engineering, and there is no reissue for a transaction history.
Graded medium. The account is consistently reported; the internal detection sequence has not been described publicly.
Compiled from public reporting, listed below. We do not name individuals, and improper access is not the same as a criminal finding. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense