COINBASE, INC.
ent_019e5f4a3fb4cf85723b78f8a0829401
Disclosures
17
State AG · SEC 8-K · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
69,461
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- COINBASE, INC.
- Normalized
- coinbase— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QHD76EP6ZKTT48
- SEC EDGAR CIK
- 0001679788
- Domain
- coinbase.com
Disclosure history (17)newest first
- Indiana State AGas victim2025-12-11
Coinbase Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-11-18 and was reported on 2025-12-11. 2 Indiana residents were affected. 32 individuals affected in total.
- Indiana State AGas victim2025-05-30
Coinbase Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-26 and was reported on 2025-05-30. 288 Indiana residents were affected. 69,461 individuals affected in total.
- Nebraska State AGas victim2025-05-30
Coinbase Inc disclosed a data breach involving insider threat actors at overseas retail support locations who improperly accessed customer information. The incident involved the exfiltration of personal identifiers, government ID images, and account data. A third party attempted to extort $20 million; Coinbase refused payment, established a $20M reward fund, fired the insiders, and notified affected individuals via state AG filings. No passwords or private keys were compromised.
- New Hampshire State AGas victim2025-05-27
Coinbase Inc. notified the New Hampshire Attorney General of an insider threat incident where overseas support employees improperly accessed customer account information. A third party claimed to have obtained this data and demanded a $20 million ransom, which Coinbase refused. Approximately 454 New Hampshire residents were potentially impacted. Coinbase suspended the employees, notified customers, and is offering credit monitoring.
- California State AGas victim2025-05-20
Coinbase, Inc. disclosed that a small number of individuals performing services at overseas retail support locations improperly accessed customer information, including personal identifiers, government ID images, and account details. The incident occurred on December 26, 2024. Coinbase fired the involved individuals, referred the case to law enforcement, and implemented enhanced security controls. A third party attempted to extort $20 million, which Coinbase refused to pay, instead creating a reward fund. Affected customers are offered credit monitoring.
- Montana State AGas victim2025-05-20
Coinbase Inc. disclosed that a small number of individuals performing services for Coinbase at overseas retail support locations improperly accessed customer information. The incident involved insider misuse of valid accounts to collect PII (names, DOB, masked SSNs, IDs) and account data. A third party subsequently attempted to extort $20 million. Coinbase fired the insiders, engaged law enforcement, and offered credit monitoring.
- Washington State AGas victim2025-05-20
Coinbase, Inc. reported an insider threat incident where individuals performing services at overseas retail support locations improperly accessed customer data, including PII and financial identifiers. The breach occurred between Dec 26, 2024, and May 5, 2025. A third party attempted to extort $20M. Coinbase fired the insiders, engaged law enforcement, and offered credit monitoring to affected individuals.
- Maine State AGas victim2025-05-20
Coinbase, Inc. reported an insider wrongdoing incident where individuals performing services for Coinbase at overseas retail support locations improperly accessed customer information. The breach occurred on 12/26/2024, was discovered on 05/11/2025, and affected approximately 69,461 individuals, including 217 Maine residents. Data involved included personal identifiers, government ID images, and account information. A third party attempted to extort $20 million. Coinbase fired the individuals, referred the case to law enforcement, and offered one year of credit monitoring.
- Massachusetts State AGas victim2025-05-20
Coinbase, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-05-20. 2,050 Massachusetts residents were affected.
- FEDERALSEC 8-Kas victim2025-05-15
Coinbase, Inc. disclosed a material incident (Item 1.05) filed May 15, 2025. Overseas contractors/employees were bribed to exfiltrate customer and internal data. Compromised data: names, addresses, masked SSNs, masked bank accounts, government IDs, transaction history. No passwords, private keys, or fund access. Coinbase refused extortion demand and cooperated with law enforcement. Estimated remediation/reimbursement costs: $180M-$400M.
- Illinois State AGas victim2025-05-01
COINBASE, INC. filed a data-breach notice with the Illinois Attorney General in May 2025 (case 25-05-163). The register records the breach as discovered on May 11, 2025. Personal information types reported: drivers license, passport number. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Maine State AGas victim2024-07-16
Coinbase, Inc. reported an inadvertent disclosure of customer data (name, bank account, and routing numbers) resulting from a third-party bank's security incident. The bank mistakenly uploaded a file containing transaction data to an external location. 154 individuals were affected, including 1 Maine resident. Coinbase notified affected individuals on July 15, 2024.
- Massachusetts State AGas victim2024-07-16
Coinbase, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-07-16. 2 Massachusetts residents were affected.
- Massachusetts State AGas victim2021-10-13
Coinbase, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-10-13. 98 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2021-10-07
Coinbase notified Montana AG of unauthorized access to customer accounts between March and May 2021. Attackers used phishing/social engineering to steal credentials and exploited an SMS 2FA flaw. At least 6,000 customers lost funds. Coinbase reimbursed losses, updated recovery protocols, and offered credit monitoring.
- Indiana State AGas victim2021-09-27
Coinbase, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-03-17 and was reported on 2021-09-27. 78 Indiana residents were affected. 6,159 individuals affected in total.
- California State AGas victim2021-09-27
Coinbase, Inc. disclosed that between March and May 20, 2021, unauthorized third parties accessed at least 6,000 customer accounts. Attackers used compromised credentials (email, password, phone) obtained via phishing/social engineering and exploited a flaw in Coinbase's SMS Account Recovery process to bypass two-factor authentication. Funds were transferred to external crypto wallets. Coinbase reimbursed affected customers, updated recovery protocols, and offered credit monitoring.