Coinbase Cartel is a cyber-extortion group that emerged around September 2025 and is best characterized as an exfiltration-first, encryption-less extortion operation rather than a conventional ransomware crew. The group has publicly rejected the ransomware label in some of its own branding and is associated with data-theft-only coercion, staged leak-site disclosures, and pressure tactics centered on publishing stolen information rather than disrupting victim operations through file encryption. Reporting through 2026 indicates the group rapidly accumulated dozens of claimed victims and at one stage exceeded 100 victim claims, although its public posting volume later declined sharply. The actor has shown a particular focus on technology-oriented targets and developer environments, including incidents involving source code theft and extortion. A notable publicly reported case involved unauthorized access to a software company’s GitHub environment through compromised credentials, followed by theft of source code and extortion demands. Coinbase Cartel has also been described as having a history of targeting technology companies and publishing stolen code on leak sites. Operationally, Coinbase Cartel is linked to leak-site-based extortion workflows that track victim status through staged publication states and emphasize reputational and commercial pressure. Available reporting consistently describes the group as prioritizing data exfiltration while leaving systems available, distinguishing it from crews whose primary leverage is encryption. This places it within the broader trend of modern extortion actors reducing dwell time and operational noise by avoiding encryptors. Researchers have linked Coinbase Cartel to the broader English-speaking cybercriminal ecosystem associated with ShinyHunters, Scattered Spider, Lapsus$, and the Silent Ransom Group. Those associations suggest overlap in tradecraft and social-engineering-centric intrusion culture, particularly around stolen credentials, cloud and SaaS abuse, and compromise of developer or identity infrastructure. However, high-confidence public reporting supports describing Coinbase Cartel primarily as a distinct extortion brand rather than conclusively as a formal sub-group of any one of those actors. An alias observed in reporting is Storm-2981.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group that suffered the steepest decline in Q2 2026, possibly reflecting operational disruption.
Described as a prolific leak operation.
Ransomware group claiming attacks across multiple regions, including victims in South Korea, the United States, and Slovenia.
Active ransomware operation highlighted as part of the evolving ransomware ecosystem of affiliates, brokers, access sellers, extortion specialists, and initial access operators.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.