MisusePrivilege AbuseData MishandlingEmployee Data InvolvedCustomer Data InvolvedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
COINBASE, INC.
bd_2406100bb1153d9e · schema v1 · pii pii-v1
Full breach record for COINBASE, INC. →Coinbase, Inc. disclosed that a small number of individuals performing services at overseas retail support locations improperly accessed customer information, including personal identifiers, government ID images, and account details. The incident occurred on December 26, 2024. Coinbase fired the involved individuals, referred the case to law enforcement, and implemented enhanced security controls. A third party attempted to extort $20 million, which Coinbase refused to pay, instead creating a reward fund. Affected customers are offered credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6fcf4d20742c3a72Montana State AGfiled 2025-05-20Verified
- bd_7388d192de2195c0Washington State AGfiled 2025-05-20Verified
- bd_6b9a0642ea872c25SEC 8-Kfiled 2025-05-15(5d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-602952
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 20, 2025
- Raw hash
- c76c4011782485f51d18a82ebd3dc9c77d23a928a08a4fe300ad3b2f21ba0d4c
Reporting entity
- Name
- COINBASE, INC.norm: coinbase
- Domain
- coinbase.com
Victim entity
- Name
- COINBASE, INC.norm: coinbase
- Domain
- coinbase.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 2, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Insider
- Threat actor
- InternalFinancial
- Regulator citations
- Referred the case to U.S. and international agencies
- Initial access
- insider_action
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.