Skip to main content

Coinbase estimates the potential impact of a breach at between 180 and 400 million dollars

Coinbase reported that attackers obtained data from a portion of its customers after bribing certain employees and contractors.

CybersecuritySeintec Team2-3 min read
Coinbase estimates the potential impact of a breach at between 180 and 400 million dollars

News summary

Coinbase reported that attackers obtained data from a portion of its customers after bribing certain employees and contractors. The company rejected a ransom demand and estimated a potential cost of between 180 and 400 million dollars.

Insider and third-party risk require granular permissions, traceability and the ability to detect data queries that do not align with each user’s regular work.

Source: Reuters — 15 May 2025

What happened

In May 2025 Coinbase disclosed that attackers had obtained data on some of its customers after bribing certain employees and contractors with access to support systems. The company refused to pay the ransom demanded and estimated a potential impact of between $180 million and $400 million.

Access was not gained through a technical vulnerability but by buying the cooperation of people with legitimate access to the data, pointing to an insider and third-party risk with permissions over sensitive information.

What it means for a mid-sized business

The case is a reminder that insider risk and third-party access risk (contractors, support providers) can be as significant as an external attacker, especially for businesses handling high-value customer data.

Detecting it in time requires distinguishing legitimate access from an anomalous query: someone with the correct permissions who is looking at data that does not fit their usual work.

What to review

Controls that limit the damage of a compromised insider account:

  • Granular permissions: each person only accesses the data needed for their role.
  • Logging and traceability of access to sensitive data, with alerts for unusual patterns.
  • Periodic review of contractor and outside support provider permissions.
  • A defined response procedure for extortion attempts, without improvised decisions.

Frequently Asked Questions

How did the attackers obtain the data?
According to Coinbase, by bribing employees and contractors with access to support systems, not by exploiting a technical vulnerability.
Did Coinbase pay the ransom?
No. The company refused the payment demand and estimated the incident's potential impact at between $180 million and $400 million.
What sets this case apart from a typical cyberattack?
The entry vector was human and internal: people with legitimate access who were corrupted, not a software flaw.

This type of news demonstrates that cybersecurity, cloud and business continuity must be planned together. Seintec can help you achieve this in your organisation; contact us.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.