Hackers used social engineering to trick Coinbase users

Source Cryptopolitan

Coinbase was informed as early as January 2025 about a breach involving outsourced customer support agents in India, according to a Reuters investigation. Six people familiar with the matter told the report that the crypto exchange knew that sensitive user data had been compromised via its contractor, TaskUs, months before its formal announcement in May.

In a May 14 SEC filing, TaskUs documented one section of the breach in which an Indiabased employee of TaskUs was caught taking photos of the work computer screen with her personal phone. Five of the former TaskUs workers confirmed that the employee and a suspected accomplice were allegedly bribed by hackers to get Coinbase user data.

Coinbase was immediately alerted, three of the employees and one additional source said. Shortly afterward, more than 200 employees were fired from Indore’s TaskUs center, drawing media attention in India. Initially, Coinbase blamed ‘overseas support agents,’ but now it estimates that the breach could cost the company up to 400 million dollars.

Inside the campaign to exploit Coinbase’s BPO network

Coinbase had long partnered with TaskUs, a Texas-based outsourcing firm, to cut labor costs by assigning customer support duties to offshore teams. Since 2017, TaskUs agents have handled Coinbase customer inquiries, often from countries with lower wages. In Indore, India, those agents reportedly earned between $500 and $700 per month, low enough to attract criminal bribes.

In the company’s May filing, Coinbase admitted that it didn’t know the full scale of the attack until May 11, when it received a $20 million extortion demand. In response, the company severed ties with TaskUs employees responsible for the breach as well as with some other unnamed foreign contractors. Coinbase also said it had notified regulators, reimbursed affected users, and strengthened its internal controls.

In its public statement, TaskUs acknowledged firing two staff for data theft but did not name Coinbase. The company said the two were part of a coordinated criminal campaign that had hit other service providers tied to the client.

Hackers used social engineering to trick Coinbase users

Coinbase’s crypto wallets were not directly breached in the attack. Instead, hackers used the stolen personal information to impersonate Coinbase employees in a wave of social engineering scams. They would pretend to be support agents, tricking victims into moving their crypto assets.

Security researchers believe a loosely organized group known as “the Comm” orchestrated the breach. The group comprises young hackers experienced in conducting high-profile attacks, with one of its hits being casinos and crypto firms.

A report by Fortune also stated that the hackers had different roles for their members—some bribed insiders to steal data while others executed the scams. Social media platforms such as Telegram and Discord were used to coordinate operations and split the proceeds.

The impersonation schemes, investigators noted, were more effective as those targeting Coinbase customers spoke in fluent North American English. Scammers were able to leverage the stolen info to appear credible enough to get users to turn over their crypto.

Even after the breach, Coinbase is ramping up its operations. The company recently added to the S&P 500 index and recently made a strategic acquisition announcement. CEO Brian Armstrong said he still plans to make Coinbase a leading global financial services app within the next 10 years.

The Coinbase attack comes amid major growth in crypto hacks that have exceeded $2.2 billion by 2024, Chainalysis reports, highlighting the perils of outsourcing and attackers’ increased digital sophistication.

 

Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
EUR/USD Price Forecast: Bounces off 1.1300 neighborhood; shows resilience below 23.6% Fibo.The EUR/USD pair attracts some follow-through selling for the second straight day on Wednesday and drops to a one-week low during the Asian session. Spot prices, however, rebound a few pips from the 1.1300 neighborhood and currently trade around the 1.1380 region, still down over 0.35% for the day.
Author  FXStreet
4 Month 23 Day Wed
The EUR/USD pair attracts some follow-through selling for the second straight day on Wednesday and drops to a one-week low during the Asian session. Spot prices, however, rebound a few pips from the 1.1300 neighborhood and currently trade around the 1.1380 region, still down over 0.35% for the day.
placeholder
Bitcoin Must Clear This Critical Cost Basis Level For Continued Upside, Analyst SaysIn a recent CryptoQuant Quicktake post, contributor Crazzyblockk highlighted key Bitcoin (BTC) cost basis zones that the leading cryptocurrency must clear – or avoid breaking below – to
Author  NewsBTC
4 Month 23 Day Wed
In a recent CryptoQuant Quicktake post, contributor Crazzyblockk highlighted key Bitcoin (BTC) cost basis zones that the leading cryptocurrency must clear – or avoid breaking below – to
placeholder
US Dollar Index surges toward 99.00, rebounds from six-week lowsThe US Dollar Index (DXY), which measures the value of the US Dollar (USD) against six major currencies, has rebounded from a six-week low of 98.58 and is trading higher near 98.90 during the Asian hours on Tuesday. Traders would likely observe the release of the JOLTS Job Openings later on Tuesday.
Author  FXStreet
Yesterday 06: 22
The US Dollar Index (DXY), which measures the value of the US Dollar (USD) against six major currencies, has rebounded from a six-week low of 98.58 and is trading higher near 98.90 during the Asian hours on Tuesday. Traders would likely observe the release of the JOLTS Job Openings later on Tuesday.
placeholder
BNB Price Forecast: BNB recovery receives boost as trading volume hits $11.35 billion, highest yearly levelBNB (BNB) is extending its recovery, trading around $670 on Tuesday after rebounding from a key level over the weekend. On-chain data and technical outlook suggest a rally ahead as BNB breaks above the symmetrical triangle pattern, with ecosystem trading volume and stablecoin activity surging.
Author  FXStreet
Yesterday 06: 23
BNB (BNB) is extending its recovery, trading around $670 on Tuesday after rebounding from a key level over the weekend. On-chain data and technical outlook suggest a rally ahead as BNB breaks above the symmetrical triangle pattern, with ecosystem trading volume and stablecoin activity surging.
placeholder
Solana Down 13%, But This Indicator Just Turned BullishAn analyst has pointed out how Solana has recently formed a signal on the Tom Demark (TD) Sequential that could imply a potential reversal for the asset’s price. Solana Has Seen A TD Sequential
Author  NewsBTC
Yesterday 06: 21
An analyst has pointed out how Solana has recently formed a signal on the Tom Demark (TD) Sequential that could imply a potential reversal for the asset’s price. Solana Has Seen A TD Sequential
goTop
quote