COINBASE, INC.
bd_2406100bb1153d9e · schema v1 · pii pii-v1
Full breach record for COINBASE, INC. →4 incidents on fileCoinbase, Inc. disclosed that a small number of individuals performing services at overseas retail support locations improperly accessed customer information, including personal identifiers, government ID images, and account details. The incident occurred on December 26, 2024. Coinbase fired the involved individuals, referred the case to law enforcement, and implemented enhanced security controls. A third party attempted to extort $20 million, which Coinbase refused to pay, instead creating a reward fund. Affected customers are offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 26, 2024
Begins
May 20, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Montana State AGbd_6fcf4d20742c3a722025-05-20Verified
- Washington State AGbd_7388d192de2195c02025-05-20Verified
- Maine State AGbd_b45c155746e8d50c2025-05-20Verified
- Massachusetts State AGbd_fa2703e77095dfa82025-05-20Verified
Show 5 more filings ↓Show fewer ↑up to 19d gap
- SEC 8-Kbd_6b9a0642ea872c252025-05-15 · +5dCandidate
- New Hampshire State AGbd_bc2dd2c7c34bf3fe2025-05-27 · +7dVerified
- Indiana State AGbd_a3874b13126e95f92025-05-30 · +10dVerified
- Nebraska State AGbd_eb31106dc74935862025-05-30 · +10dVerified
- Illinois State AGbd_a0715ceb81713b592025-05-01 · +19dCandidate
Filing propagation · 10 filings · 9 states
View merged incident ↗Pattern: first filing May 1 (IL), last May 30 (NE) — a 29-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.