Coinbase Cartel is a cyber-extortion group active since at least September 2025 that operates primarily as a data-theft-only extortion actor rather than a conventional encryption-focused ransomware crew. The group has publicly rejected the ransomware label in some reporting and is characterized by stealing data, maintaining victim system availability, and coercing payment through threats of publication on leak infrastructure. Its leak operations have used staged disclosure states and public victim naming, and the group has been tracked among active extortion brands during 2026 despite a sharp decline in public victim-post volume in Q2 2026. The actor has been associated with attacks against technology companies and source-code repositories, including incidents in which compromised credentials or tokens enabled access to developer environments and codebases. In one publicly reported case, the group claimed responsibility for a compromise of a software company’s GitHub environment and threatened to leak stolen source code unless paid. Reporting also describes a history of publishing stolen code on leak sites. More broadly, Coinbase Cartel has been linked by researchers to the English-speaking cybercriminal ecosystem surrounding ShinyHunters, Scattered Spider, and Lapsus$, placing it in a milieu known for social engineering, stolen credentials, cloud and SaaS abuse, and compromise of developer environments. Some reporting also places the group alongside the Silent Ransom Group lineage as an emerging data-extortion operation. Known aliases include STORM-2981 and the name Coinbase Cartel itself. The group has claimed victims in multiple regions, including South Korea, Slovenia, and the United States, and has been described as targeting technology companies in particular. Public reporting supports extortion and data exfiltration as core behaviors, while broader ecosystem links suggest overlap with credential-centric and social-engineering-heavy intrusion tradecraft; however, only exfiltration and extortion are directly established at high confidence for the actor itself from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.