Core Insights - Coinbase reported a significant data breach involving cyber criminals bribing overseas support agents to steal customer data, which may cost the company up to $400 million to address [1][5]. Group 1: Incident Details - The company received an email on May 11 from an individual claiming to have obtained sensitive information about certain customer accounts and internal documentation [2]. - The email demanded a ransom in exchange for not publicly disclosing the stolen information, but Coinbase has not complied and is cooperating with law enforcement [3][6]. - The breach did not compromise passwords or private keys, but sensitive data such as names, addresses, phone numbers, emails, masked bank account numbers, and the last four digits of social security numbers were affected [4][5]. Group 2: Company Response - Coinbase detected the breach independently and took immediate action by terminating the involved employees, warning affected customers, and enhancing fraud monitoring protections [5]. - The company is establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible for the attack, while refusing to pay the $20 million ransom demand [6]. - Coinbase operates the largest crypto exchange in the U.S. and recently announced an acquisition aimed at expanding its global reach, alongside gaining entry to the S&P 500 stock index [6].
Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom