COINBASE, INC.
bd_7388d192de2195c0 · schema v1 · pii pii-v1
Full breach record for COINBASE, INC. →4 incidents on fileCoinbase, Inc. reported an insider threat incident where individuals performing services at overseas retail support locations improperly accessed customer data, including PII and financial identifiers. The breach occurred between Dec 26, 2024, and May 5, 2025. A third party attempted to extort $20M. Coinbase fired the insiders, engaged law enforcement, and offered credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 26, 2024
Begins
May 11, 2025
Discovered
May 20, 2025
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- California State AGbd_2406100bb1153d9e2025-05-20Verified
- Montana State AGbd_6fcf4d20742c3a722025-05-20Verified
- Maine State AGbd_b45c155746e8d50c2025-05-20Verified
- Massachusetts State AGbd_fa2703e77095dfa82025-05-20Verified
Show 5 more filings ↓Show fewer ↑up to 19d gap
- SEC 8-Kbd_6b9a0642ea872c252025-05-15 · +5dCandidate
- New Hampshire State AGbd_bc2dd2c7c34bf3fe2025-05-27 · +7dVerified
- Indiana State AGbd_a3874b13126e95f92025-05-30 · +10dVerified
- Nebraska State AGbd_eb31106dc74935862025-05-30 · +10dVerified
- Illinois State AGbd_a0715ceb81713b592025-05-01 · +19dCandidate
Filing propagation · 10 filings · 9 states
View merged incident ↗Pattern: first filing May 1 (IL), last May 30 (NE) — a 29-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.