DisclosureLens
MisuseFinancial ServicesTechnologyFinancePrivilege AbuseBECRansom DemandedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDPIIMediumContained

COINBASE, INC.

bd_6fcf4d20742c3a72 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

May 20, 2025

To disclose

Affected

160state residents only

Linked

10 filings

Confidence

67%
Full breach record for COINBASE, INC.4 incidents on file

Coinbase Inc. disclosed that a small number of individuals performing services for Coinbase at overseas retail support locations improperly accessed customer information. The incident involved insider misuse of valid accounts to collect PII (names, DOB, masked SSNs, IDs) and account data. A third party subsequently attempted to extort $20 million. Coinbase fired the insiders, engaged law enforcement, and offered credit monitoring.

Incident timeline — partial

? — ?

Breach window unknown

May 20, 2025

Filed

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

This filing is one of 10 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 19d gap

Filing propagation · 10 filings · 9 states

View merged incident ↗

Pattern: first filing May 1 (IL), last May 30 (NE) — a 29-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.