Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
COINBASE, INC.
bd_b312e90e0503e80c · schema v1 · pii pii-v1
Full breach record for COINBASE, INC. →Coinbase, Inc. disclosed a breach between March and May 2021 where approximately 6,000 customers were targeted by a phishing campaign. Attackers used stolen credentials and exploited a flaw in Coinbase's SMS-based account recovery to access accounts and steal cryptocurrency. Affected data included names, addresses, DOBs, and transaction history. Coinbase reimbursed losses, updated SMS recovery protocols, and offered credit monitoring.
California clockDiscovered May 20, 2021 → Notified Sep 24, 2021127d ✗ CA 60-day late19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_72c7989c67aa78dfMontana State AGfiled 2021-10-07(10d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545815
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 27, 2021
- Raw hash
- 77143cdf5e57e0d13c0874755568fe241f4b1b851429a22ba7bc212ff4b4e0e6
Reporting entity
- Name
- COINBASE, INC.norm: coinbase
- Domain
- coinbase.com
Victim entity
- Name
- COINBASE, INC.norm: coinbase
- Domain
- coinbase.com
Incident
- Discovered
- May 20, 2021
- Materiality determined
- —
- Notification sent
- Sep 24, 2021
- Affected individuals
- 6,000
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(130 days from discovery to filing)
- Compliance flags
- CA 60-day late · 127d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 20, 2021→ Notified: Sep 24, 2021127d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.