COINBASE, INC.
bd_72c7989c67aa78df · schema v1 · pii pii-v1
Full breach record for COINBASE, INC. →4 incidents on fileCoinbase notified Montana AG of unauthorized access to customer accounts between March and May 2021. Attackers used phishing/social engineering to steal credentials and exploited an SMS 2FA flaw. At least 6,000 customers lost funds. Coinbase reimbursed losses, updated recovery protocols, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 1, 2021
Begins
Oct 7, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_ab7cb7d82e3a889b2021-10-13 · +6dVerified
- Indiana State AGbd_6106f156a9b2a0972021-09-27 · +10dVerified
- California State AGbd_b312e90e0503e80c2021-09-27 · +10dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Sep 27 (IN), last Oct 13 (MA) — a 16-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.