Tech

Coinbase said cyber crooks stole customer information and demanded $20 million ransom payment

Share
Share
Coinbase said cyber crooks stole customer information and demanded $20 million ransom payment
The Coinbase logo covers the Nasdaq MarketSite in New York’s Times Square, April 14, 2021. Credit: AP Photo/Richard Drew, File

Coinbase, the largest cryptocurrency exchange based in the U.S., said Thursday that criminals had improperly obtained personal data on the exchange’s customers for use in crypto-stealing scams and were demanding a $20 million payment not to publicly release the info.

Coinbase CEO Brian Armstrong said in a social media post that criminals had bribed some of the company’s customer service agents who live outside the U.S. to hand over personal data on customers, like names, dates of birth and partial social security numbers.

“(The stolen data) allows them to conduct social engineering attacks where they can call our customers impersonating Coinbase customer support and try to trick them into sending their funds to the attackers,” Armstrong said.

Social engineering is a popular hacking strategy, as humans tend to be the weakest link in any network. Many large companies have suffered hacks and data breaches as a result of such scams in recent years.

Coinbase did not specify how many customers had their data stolen or fell prey to social engineering scams. But the company did pledge to reimburse any who did.

In a filing with the Securities and Exchange Commission, Coinbase estimated that it would have to spend between $180 million to $400 million “relating to remediation costs and voluntary customer reimbursements relating to this incident.”

The SEC filing said that the company had, “in previous months,” detected some of its customer service agents “accessing data without business need.” Those employees had been fired, and the company said it stepped up its fraud prevention efforts.

Coinbase said it received an email from the attackers on Sunday demanding a ransom of $20 million worth of bitcoin not to publicly release the customer data they had stolen.

Armstrong said the company was refusing to pay the ransom and would instead offer a $20 million bounty for anyone who provided information that led to the attackers’ arrest.

“For these would-be extortionists or anyone seeking to harm Coinbase customers, know that we will prosecute you and bring you to justice,” Armstrong said. “And know you have my answer.”

© 2025 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed without permission.

Citation:
Coinbase said cyber crooks stole customer information and demanded $20 million ransom payment (2025, May 15)
retrieved 15 May 2025
from

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
China’s 2035 climate plan must aim high
Tech

China’s 2035 climate plan must aim high

Credit: Pixabay/CC0 Public Domain China will need to generate more than half...

She let ChatGPT read her coffee grounds – then filed for divorce
Tech

She let ChatGPT read her coffee grounds – then filed for divorce

A Greek couple thought it would be fun to use ChatGPT as...

SanDisk’s Ultra QLC roadmap targets 256TB and 512TB SSDs using new Stargate architecture
Tech

SanDisk’s Ultra QLC roadmap targets 256TB and 512TB SSDs using new Stargate architecture

SanDisk plans 256TB and 512TB SSDs using new Stargate controller Stargate will...