COINBASE, INC.
ent_019e5f4a3fb4cf85723b78f8a0829401
Disclosures
10
State AG · SEC 8-K · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
69,461
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- COINBASE, INC.
- Normalized
- coinbase— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QHD76EP6ZKTT48
- SEC EDGAR CIK
- 0001679788
- Domain
- coinbase.com
Disclosure history (10)newest first
- 🏎️Indiana State AGas victim2025-12-11
Coinbase Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-11-18 and was reported on 2025-12-11. 2 Indiana residents were affected. 32 individuals affected in total.
- 🏎️Indiana State AGas victim2025-05-30
Coinbase Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-26 and was reported on 2025-05-30. 288 Indiana residents were affected. 69,461 individuals affected in total.
- 🐻California State AGas victim2025-05-20
Coinbase, Inc. disclosed that a small number of individuals performing services at overseas retail support locations improperly accessed customer information, including personal identifiers, government ID images, and account details. The incident occurred on December 26, 2024. Coinbase fired the involved individuals, referred the case to law enforcement, and implemented enhanced security controls. A third party attempted to extort $20 million, which Coinbase refused to pay, instead creating a reward fund. Affected customers are offered credit monitoring.
- 🦬Montana State AGas victim2025-05-20
Coinbase Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2025-05-20. The breach occurred on 05/11/2025. 160 Montana residents were affected.
- 🌲Washington State AGas victim2025-05-20
Coinbase, Inc, a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2025-05-11 and filed notice on 2025-05-20. 3,337 Washington residents were affected. 9 days elapsed between awareness and notification. 136 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2025-05-20
Coinbase, Inc. reported an insider wrongdoing incident that affected 217 Maine residents. The breach occurred on December 26, 2024, and was discovered on May 11, 2025. Affected individuals were notified on May 30, 2025, and offered one year of free credit monitoring and identity protection services.
- FEDERALSEC 8-Kas victim2025-05-15
Coinbase, Inc. disclosed a material incident (Item 1.05) filed May 15, 2025. Overseas contractors/employees were bribed to exfiltrate customer and internal data. Compromised data: names, addresses, masked SSNs, masked bank accounts, government IDs, transaction history. No passwords, private keys, or fund access. Coinbase refused extortion demand and cooperated with law enforcement. Estimated remediation/reimbursement costs: $180M-$400M.
- 🦞Maine State AGas victim2024-07-16
Coinbase, Inc. experienced an inadvertent disclosure on July 11, 2024, which was discovered the same day. The breach affected 154 individuals, including one resident of Maine. Written notifications were sent to the affected individuals on July 15, 2024. The company did not offer identity theft protection services.
- 🦬Montana State AGas victim2021-10-07
Coinbase reported a data breach to the Montana Attorney General. The breach was reported on 2021-10-07. The breach occurred from 3/1/2021 to 5/20/2021. 7 Montana residents were affected.
- 🐻California State AGas victim2021-09-27
Coinbase, Inc. disclosed a breach between March and May 2021 where approximately 6,000 customers were targeted by a phishing campaign. Attackers used stolen credentials and exploited a flaw in Coinbase's SMS-based account recovery to access accounts and steal cryptocurrency. Affected data included names, addresses, DOBs, and transaction history. Coinbase reimbursed losses, updated SMS recovery protocols, and offered credit monitoring.