Coinbase confirmed an insider data breach in which a single contractor improperly accessed customer information affecting approximately 30 customers. Coinbase said its security team detected the activity, the contractor no longer provides services to the company, impacted users were notified, and identity theft protection was offered; Coinbase also reported the incident to relevant regulators.
The disclosure followed brief Telegram posts by threat actors showing screenshots of an internal Coinbase support interface that appeared to expose access to sensitive customer data, including names, email addresses, phone numbers, dates of birth, and KYC information (and, per the leaked interface screenshots, potentially wallet balances and transaction details). Reporting indicated the incident is separate from the previously disclosed TaskUs-related insider breach, and it remains unclear whether the group that posted the screenshots (reported as “Scattered Lapsus Hunters”) conducted the access or merely obtained and shared the data; the incident highlights ongoing targeting of BPO/contractor ecosystems due to their privileged access to internal tools and customer records.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Coinbase publicly confirmed the insider-related data access incident in early February 2026, linking it to the leaked support tool screenshots and stating that the breach affected about 30 customers. The company emphasized that the incident was separate from the earlier TaskUs-associated breach.
Before Coinbase publicly confirmed the incident, a threat actor cluster calling itself 'Scattered Lapsus Hunters' briefly posted and then deleted screenshots on Telegram showing an internal Coinbase support interface with access to sensitive customer data. It remained unclear whether the group conducted the breach or only obtained the leaked material.
After detecting the incident, Coinbase notified impacted customers and offered identity theft protection. The company said roughly 30 users were affected.
Coinbase's security team detected the unauthorized access during 2025, determined it was an insider-related incident, and removed the contractor from providing services. The company said the event was separate from the previously disclosed TaskUs-related insider breach.
In December 2025, a contractor improperly accessed Coinbase customer information affecting approximately 30 users. The exposed data included personal details such as names, email addresses, phone numbers, and KYC information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.