A former Coinbase customer service agent was arrested in Hyderabad, India, for assisting hackers in stealing sensitive customer data from the cryptocurrency exchange. The breach, which occurred earlier in the year, involved hackers bribing employees of TaskUs, a customer support outsourcing firm, to gain unauthorized access to Coinbase's systems. The attackers demanded a $20 million ransom to prevent the publication of the stolen data, which included names, dates of birth, partial Social Security numbers, addresses, phone numbers, email addresses, and, for some, scanned KYC documents. Coinbase reported that approximately 69,500 customers were affected by the breach, and the company responded by shutting down the implicated TaskUs department and cooperating with law enforcement.
The arrest of the former agent highlights the ongoing risk of insider threats within organizations, particularly those handling sensitive financial data. Coinbase CEO Brian Armstrong confirmed the arrest and indicated that further detentions may follow as the investigation continues. The incident also drew attention to the delayed disclosure of the breach and the subsequent layoffs at TaskUs. This case underscores the importance of robust insider threat detection and the risks associated with third-party service providers in the financial sector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
By the end of December, reporting indicated that new arrests had been made in connection with the Coinbase insider data scandal. The developments suggested the law-enforcement investigation had expanded beyond the first arrested former support agent.
In an unrelated case, the Brooklyn District Attorney's Office charged Ronald Spektor with impersonating a Coinbase representative to steal nearly $16 million from about 100 victims. Coinbase said it assisted the investigation, and authorities recovered over $600,000.
Following the discovery of the insider-assisted breach, an entire TaskUs department was shut down and several employees of the outsourcing firm were laid off. The response underscored the role of third-party support operations in the incident.
Coinbase declined to pay the extortion demand and instead created a $20 million reward fund for information leading to the attackers' arrest. The company publicly framed the incident as an insider-assisted breach involving overseas support staff.
Indian police arrested a former Coinbase customer service agent accused of helping hackers steal customer data from Coinbase's systems. Coinbase CEO Brian Armstrong confirmed the arrest and said additional arrests are expected.
After obtaining the customer data, the attackers demanded $20 million from Coinbase in exchange for not publishing it. Criminals also used the stolen information to conduct social engineering attacks against Coinbase users.
Hackers bribed customer service representatives or contractors working through outsourcing firm TaskUs to access Coinbase customer information. The insider access exposed sensitive data for about 69,500 customers, including personal and KYC-related details, but not private keys or 2FA codes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.