Coinbase Data Breach Exposes 69,000+ Customer Records in $400 Million Security Incident

Court documents have disclosed new information about a significant data breach at Coinbase, revealing that an overseas customer support worker initiated the security incident that compromised personal information of more than 69,000 customers.

Employee at Outsourced Firm Orchestrated Data Theft

Investigators identified Ashita Mishra, an employee at outsourcing company TaskUs, as the primary actor behind the breach. Court filings allege that Mishra systematically photographed Coinbase customer data from company computers using her mobile device, with the intent to sell the information to criminal organizations.

The breach affected 69,461 Coinbase users and exposed sensitive personal data including full names, residential addresses, phone numbers, email addresses, partial Social Security numbers, masked bank account information, government identification documents, and account data.

Organized Criminal Network Behind Breach

The investigation reveals that Mishra did not act alone. Court documents describe a “hub-and-spoke conspiracy” involving multiple TaskUs employees who unknowingly participated in the data theft operation. This structure ensured the continued flow of stolen information even if individual participants were discovered or removed.

The organized approach allowed the criminal network to maintain access to customer data across different departments and shifts, making detection more difficult for security teams.

Coinbase Rejects Ransom Demands, Prepares Customer Compensation

Coinbase confirmed that it refused to pay ransom demands made by the criminals behind the breach. The cryptocurrency exchange has instead committed to covering customer losses directly, with estimated remediation costs ranging between $180 million and $400 million.

The company took immediate action following the discovery of the breach, terminating its relationship with the involved TaskUs personnel and other overseas support agents. Coinbase has implemented additional internal security controls designed to prevent similar incidents in future operations.

Industry Impact on Crypto Security Practices

This breach highlights ongoing security challenges faced by cryptocurrency exchanges that rely on third-party customer support services. The incident demonstrates the risks associated with outsourcing customer data handling to external organizations, particularly those operating in different jurisdictions.

The case serves as a reminder for crypto platforms to maintain strict oversight of all personnel with access to customer information, regardless of their employment status or geographic location. Industry experts expect this incident to prompt other exchanges to review their third-party security protocols.

Coinbase continues to cooperate with law enforcement agencies investigating the breach and has committed to transparency in communicating with affected customers about remediation efforts.

Source: coinbase.com

Related posts

Infingame sees operators moving toward self-service casino analytics

Sweepstakes.io Launches Independent Comparison and Review Platform for the iGaming Industry

Infingame brings a performance-first approach to aggregation at SBC Summit Lisbon

This website uses cookies to improve your experience. We'll assume you're ok with this. Read More