Coinbase Breach Traced to 0-Per-Image Insider Scheme Coinbase Breach Traced to 0-Per-Image Insider Scheme

Coinbase Breach Traced to $200-Per-Image Insider Scheme

Newly released court documents have shed light on the Coinbase data breach. A major suspect has been identified in the exploit, which the exchange revealed had impacted ‘less than 1%’ of its monthly active users.

According to court documents, employees at a Coinbase outsourced customer service firm, TaskUs, allegedly stole sensitive customer information. This included Social Security numbers, bank account details, and more.

Sponsored

Sponsored

Court Documents Reveal Insider Plot Behind Coinbase Data Breach 

The incident came to public attention in May 2025. At the time, Coinbase disclosed that attackers bribed rogue support agents to access user data. BeInCrypto reported that the bad actors demanded a $20 million ransom. 

The exchange declined to pay it and instead announced a $20 million bounty for information that could help identify and prosecute those behind the attack. Now, the amended class action complaint, filed in the US District Court for the Southern District of New York, traces the breach back to TaskUs. It is a business process outsourcing company that Coinbase used for customer support. 

“According to personnel knowledgeable of the data breach, in 2024, criminal actors began a campaign of outreach to target and recruit TaskUs employees to join a conspiracy to exfiltrate PII of Coinbase users so that those criminals could steal cryptocurrency assets held by those users. As early as September 2024, TaskUs employee Ashita Mishra joined the conspiracy by agreeing to sell highly sensitive Coinbase user data to those criminals,” the filing reads.

Beginning in September 2024, a TaskUs employee in India, Ashita Mishra, allegedly started photographing sensitive customer records. Mishra then sold the stolen data to outside hackers for roughly $200 per image. The breach’s extent was vast. 

When TaskUs discovered the breach in early January 2025, Mishra’s phone alone held data on more than 10,000 Coinbase customers. Records showed that she took up to 200 photos on some days.  

According to the filings, it was a wider conspiracy involving multiple TaskUs employees who funneled stolen data to organized criminals. 

“Ms. Mishra and an accomplice operated smaller circles of disconnected TaskUs employees who participated in the conspiracy,” the documents revealed.

Sponsored

Sponsored

Furthermore, the complaint highlighted that despite uncovering the breach in early January 2025 and firing roughly 300 employees from its India-based centers, TaskUs and Coinbase did not immediately notify customers. As per the text, 

“Between January of 2025, when they became aware of the Data Breach, and May of 2025, TaskUs and Coinbase disclosed in their Form 10-Ks that they were not aware of any material data breaches impacting their respective companies.” 

Meanwhile, using the stolen details, fraudsters impersonated Coinbase representatives and convinced victims to transfer cryptocurrency into fraudulent wallets. Several plaintiffs report that the breach wiped out their life savings or retirement funds.

“The criminals utilized a standard playbook in order to carry out their scheme, successfully stealing as much as $400 million from unsuspecting victims by Coinbase’s own estimates,” the lawsuit noted.

The breach sparked widespread criticism as users reported being targeted by phishing and impersonation schemes. Furthermore, Coinbase faced a lawsuit following a decline in its stock price, which resulted in substantial investor losses.

In the aftermath, Coinbase severed ties with implicated TaskUs personnel and implemented stricter controls.

“We notified affected users and regulators immediately, reimbursed impacted customers, tightened vendor and insider controls, and ended our relationship with TaskUs,” Coinbase told Fortune.

To further strengthen its defenses, Coinbase says it is tightening its remote-work policies to reduce insider threats and prevent infiltration by foreign operatives, including North Korean actors.

The Coinbase breach illustrates the scale of damage that insider threats can cause in the crypto industry. Despite advanced technical defenses, human vulnerabilities at third-party providers remain an acute risk — one that even the world’s largest exchanges struggle to contain.

Source link

Kamina Bashir

https://beincrypto.com/coinbase-data-breach-insider-plot-court-documents/

2025-09-17 11:14:00

bitcoin
Bitcoin (BTC) $ 120,893.00 2.08%
ethereum
Ethereum (ETH) $ 4,331.94 4.03%
tether
Tether (USDT) $ 1.00 0.04%
bnb
BNB (BNB) $ 1,239.60 5.98%
xrp
XRP (XRP) $ 2.79 3.95%
solana
Solana (SOL) $ 218.61 4.41%
usd-coin
USDC (USDC) $ 0.999777 0.00%
dogecoin
Dogecoin (DOGE) $ 0.246581 4.69%
staked-ether
Lido Staked Ether (STETH) $ 4,330.85 4.06%
tron
TRON (TRX) $ 0.336685 1.42%
cardano
Cardano (ADA) $ 0.808546 3.62%
wrapped-steth
Wrapped stETH (WSTETH) $ 5,267.48 3.96%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 120,994.00 1.91%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 4,672.89 4.02%
chainlink
Chainlink (LINK) $ 21.74 3.33%
ethena-usde
Ethena USDe (USDE) $ 0.999946 0.08%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.996586 1.75%
sui
Sui (SUI) $ 3.40 4.02%
stellar
Stellar (XLM) $ 0.376645 3.14%
avalanche-2
Avalanche (AVAX) $ 28.12 3.63%
hyperliquid
Hyperliquid (HYPE) $ 43.43 7.02%
wrapped-eeth
Wrapped eETH (WEETH) $ 4,672.12 4.06%
bitcoin-cash
Bitcoin Cash (BCH) $ 575.68 1.97%
weth
WETH (WETH) $ 4,333.64 4.06%
litecoin
Litecoin (LTC) $ 118.54 0.09%
hedera-hashgraph
Hedera (HBAR) $ 0.211235 4.10%
leo-token
LEO Token (LEO) $ 9.61 0.55%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999961 0.01%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 121,005.00 2.12%
usds
USDS (USDS) $ 0.995324 0.33%
mantle
Mantle (MNT) $ 2.34 14.36%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 3.92%
usdt0
USDT0 (USDT0) $ 1.00 0.14%
the-open-network
Toncoin (TON) $ 2.72 2.25%
crypto-com-chain
Cronos (CRO) $ 0.193327 2.60%
whitebit
WhiteBIT Coin (WBT) $ 43.28 2.39%
monero
Monero (XMR) $ 334.60 0.55%
polkadot
Polkadot (DOT) $ 4.03 4.42%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.20 0.04%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.17752 5.50%
uniswap
Uniswap (UNI) $ 7.78 3.19%
dai
Dai (DAI) $ 0.99914 0.02%
okb
OKB (OKB) $ 206.63 7.49%
aave
Aave (AAVE) $ 272.07 4.19%
bitget-token
Bitget Token (BGB) $ 5.65 0.82%
ethena
Ethena (ENA) $ 0.546773 4.75%
pepe
Pepe (PEPE) $ 0.000009 4.43%
near
NEAR Protocol (NEAR) $ 2.86 4.50%
aptos
Aptos (APT) $ 4.99 4.37%
memecore
MemeCore (M) $ 2.06 0.73%