Coinbase resists $20M ransom demand over data breach

Coinbase did not disclose the number of customers affected by the data breach, but advised clients to stay vigilant against potential scams attempting to extract more information from them.

WASHINGTON — Coinbase, the leading U.S.-based cryptocurrency exchange, announced on Thursday that criminals had accessed customer data inappropriately, using it to execute crypto-theft scams and demanding $20 million to avoid releasing the data publicly.

CEO Brian Armstrong revealed in a social media update that certain customer service agents, residing outside the U.S., had been bribed into providing customer details, such as names, birth dates, and partial social security numbers.

“(The stolen data) allows them to conduct social engineering attacks where they can call our customers impersonating Coinbase customer support and try to trick them into sending their funds to the attackers,” Armstrong said.

Social engineering is a popular hacking strategy, as humans tend to be the weakest link in any network. Many large companies have suffered hacks and data breaches as a result of such scams in recent years.

Coinbase did not specify how many customers had their data stolen or fell prey to social engineering scams. But the company did pledge to reimburse any who did.

Coinbase shares fell 6% in trading around midday. The shares are still up about 22% this month due to gains in bitcoin and other cryptocurrencies.

In a filing with the Securities and Exchange Commission, Coinbase estimated that it would have to spend between $180 million to $400 million “relating to remediation costs and voluntary customer reimbursements relating to this incident.”

The SEC filing said that the company had, “in previous months,” detected some of its customer service agents “accessing data without business need.” Those employees had been fired, and the company said it stepped up its fraud prevention efforts.

Coinbase said it received an email from the attackers on Sunday demanding a ransom of $20 million worth of bitcoin not to publicly release the customer data they had stolen.

Armstrong said the company was refusing to pay the ransom and would instead offer a $20 million bounty for anyone who provided information that led to the attackers’ arrest.

“For these would-be extortionists or anyone seeking to harm Coinbase customers, know that we will prosecute you and bring you to justice,” Armstrong said. “And know you have my answer.”

Copyright 2025 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.     

You May Also Like

Knicks Fan Dumps Trash on Street to Steal Blue and Orange Trash Can

A woman branded “incredibly stupid” was filmed swiping an orange-and-blue New York…

Counterterrorism Officials Investigate Suspect’s Alleged Hate-Fueled Rampage, Report Says

Counterterrorism officers are investigating a series of attacks in Scotland after five…

Caltrans Proposes $2.5 Billion Tunnel to Stabilize Highway 101 at Last Chance Grade

California taxpayers may soon face a multibillion-dollar bill to stabilize one of…

Keir Starmer Reportedly Weighs Resignation as PM and Could Set Departure Timeline

British PM Keir Starmer could face leadership challenge amid internal troubles British…

Chicago Drive-By Shooting Injures at Least 12 Near Princeton Park, Police Say

CHICAGO (WLS) — At least 12 people were wounded Friday night in…

Suspicious Car Stopped at San Diego Mosque One Month After Christchurch Massacre

A vigilant security guard may have helped prevent another potential attack at…

Chicago-Area Juneteenth 2026 Celebrations Continue Through Weekend With Dance and Community Events

CHICAGO (WLS) — Juneteenth events across Chicago and nearby suburbs filled the…

Trump-Backed Michael Alfonso Says GOP Is Poised to Keep the House as Democrats Push Full-Blown Marxism

Michael Alfonso, a candidate for Wisconsin’s Seventh Congressional District, said Saturday on…

H5N1 Bird Flu Confirmed in Australia for First Time as Virus Reaches Every Continent

Australia has confirmed its first case of H5N1 bird flu, marking the…

Baldwin Hills Street Takeover Blocks Ambulance as LAPD Makes No Arrests

A chaotic street takeover brought a Baldwin Hills intersection to a standstill…

FBI Offers $25K Reward as Manhunt Intensifies for Kansas City Shooting Spree Suspect Near World Cup Venue

A multi-agency search is intensifying for a 22-year-old man accused of carrying…

Tourist Killed in Massive Caribbean Resort Fire as 1,690 Guests Are Evacuated

A major fire tore through the Dominican Republic resort destination of Bayahibe…