Criminal probe launched into Coinbase data theft following $400m breach

The US Department of Justice has launched an investigation into a recent cyberattack on Coinbase Global, the world's largest cryptocurrency exchange, following a data breach that exposed customer information.

Coinbase reported receiving an email from unknown threat actors on 11 May, claiming to possess information about certain customer accounts and internal documents. The company expects financial losses between $180 million and $400 million as a result of the breach.

"We have notified and are working with the DOJ and other US and international law enforcement agencies and welcome law enforcement's pursuit of criminal charges against these bad actors," said Paul Grewal, chief legal officer at Coinbase.

According to sources familiar with the matter, Coinbase itself is not under investigation. "Coinbase is not under DOJ investigation, DOJ is investigating the criminal actors," a source told Reuters on Monday.

The cybercriminals reportedly employed a social engineering attack, bribing customer representatives based in India to collect data from internal Coinbase systems. These employees have since been dismissed. The hackers subsequently demanded a $20 million ransom to prevent public disclosure of the stolen information.

Coinbase has confirmed that while attackers managed to steal some data, including names, addresses and emails, they did not gain access to login credentials or passwords. The cryptocurrency exchange disclosed the breach publicly last Thursday.

Justice Department investigators, including those from the department's criminal division in Washington, are now examining the circumstances surrounding the breach, according to Bloomberg sources.

The cyberattack represents one of the most significant data breaches in the cryptocurrency sector this year, highlighting ongoing security challenges faced by digital asset platforms despite increased regulatory scrutiny.



Share Story:

Recent Stories


Beyond compliance: Transforming document management into a strategic advantage for financial institutions
In this exclusive fireside chat, John Rockliffe, Pre-Sales Manager at d.velop, discusses the findings of Adapting to a Digital-Native World: Financial Services Document Management Beyond 2025 and explores how FSIs can turn document workflows into a competitive advantage.

Sanctions evasion in an era of conflict: Optimising KYC and monitoring to tackle crime
The ongoing war in Ukraine and resulting sanctions on Russia, and the continuing geopolitical tensions have resulted in an unprecedented increase in parties added to sanctions lists.

Achieving operational resilience in the financial sector: Navigating DORA with confidence
Operational resilience has become crucial for financial institutions navigating today's digital landscape riddled with cyber risks and challenges. The EU's Digital Operational Resilience Act (DORA) provides a harmonised framework to address these complexities, but there are key factors that financial institutions must ensure they consider.

Legacy isn’t the enemy: what FSIs can do to keep their systems up and running
In this webinar we will examine some of the steps FSIs have already taken to rigorously monitor and test systems – both manually and with AI-powered automation – while satisfying the concerns of regulators and customers.