CoinbaseCartel is a cybercriminal data-extortion group that emerged in September 2025 and has been associated with a high-volume victimization pattern across multiple sectors, including technology, manufacturing, healthcare, transportation, business services, telecommunications, and finance-adjacent organizations. The group is primarily characterized as an extortion crew focused on data theft and coercive leak-site pressure rather than conventional ransomware encryption, although some reporting has labeled its activity as ransomware. It has been linked to numerous public victim claims in 2026 and has been observed targeting organizations in the United States, Europe, and other regions. Multiple security assessments describe CoinbaseCartel as an offshoot or affiliate-aligned element of the broader ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems, with some reporting referring to a wider Scattered Lapsus$ Hunters collective. The available information supports describing CoinbaseCartel as a financially motivated cybercrime actor rather than a state-sponsored threat group. The group’s operations are associated with credential theft, use of stolen credentials, and social-engineering-driven intrusion rather than reliance on bespoke destructive malware. Reported intrusion patterns include compromise of developer and collaboration environments, such as source-code and repository platforms, followed by theft of internal data and extortion demands. In one publicly discussed case involving Grafana Labs, the actor was tied to unauthorized access to a GitHub environment and attempted to extort the victim after code theft. Separate reporting also tied the group to compromise through a Bitbucket account in an intrusion claimed against SK Telecom, indicating interest in software-development and cloud-linked access paths. CoinbaseCartel has been described as maintaining a leak site and publicly naming victims to increase pressure. Reporting indicates the group rapidly expanded its victim count during 2026, including growth from dozens of incidents in early 2026 and a broader tally reaching well over 100 claimed victims. Sector reporting has specifically noted an apparent focus on FinTech and crypto-adjacent organizations, though the victim set is not limited to those industries. Known alias usage in the available reporting is limited to stylistic variants of the same name, including coinbasecartel and CoinbaseCartel. No high-confidence sub-groups are identified in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the threat group responsible for a ransomware attack and data breach affecting Caterpillar.
Conducting a ransomware attack against Colliers Real Estate.
Conducting a ransomware attack resulting in a data breach against Axiom GlobalNEW.
Named as an active ransomware group operating during the period discussed, contributing to frequent victimization across sectors including education and healthcare.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.