Coinbase, Inc. disclosed a breach between March and May 2021 where approximately 6,000 customers were targeted by a phishing campaign. Attackers used stolen credentials and exploited a flaw in Coinbase's SMS-based account recovery to access accounts and steal cryptocurrency. Affected data included names, addresses, DOBs, and transaction history. Coinbase reimbursed losses, updated SMS recovery protocols, and offered credit monitoring.
Affected (this filing): 6,000