Feb 06, 2026, 12:35 AM
Coinbase, the American cryptocurrency giant, has admitted a new data leak. One of its subcontractors abused its access to the internal support tool to consult the data of some of the customers. This incident comes less than a year after a similar violation. Here again, it was a service provider who was at the origin of the leak.
[COLOR=rgb(184, 49, 47)]Coinbase[/COLOR], the New York-based cryptocurrency exchange, announces that it has suffered a new data leak. The incident occurred during the month of December 2025, reports Bleeping Computer.
As the number 2 exchange in the crypto market explains, its security team discovered that a “single Coinbase subcontractor” consulted customer information by abusing its access to the internal support interface. This service provider, in charge of customer support, accessed “inappropriately customer information, which affected a very small number of users”.
The data of only 30 investors is affected. Information accessed includes email address, name, date of birth, phone number, wallet balances and transaction histories.
In addition, data relating to the KYC (Know Your Customer) procedure. Mainly deployed in the financial and banking sectors, the KYC procedure makes it possible to control the identity of users online.Its main aim is to combat illegal activities, in particular money laundering, fraud and the financing of terrorism.Many financial institutions, including cryptocurrency platforms approved by law, require the completion of a KYC form before any transaction.
[HEADING=1]Data in the hands of cybercriminals[/HEADING]
Unsurprisingly, Coinbase took care to fire the person who viewed the data. The New York company indicates that “the person concerned no longer works for Coinbase”. In addition, affected users “were informed last year and benefited from identity theft protection services and other advice.” Finally, Coinbase explains that it “reported this incident to the competent authorities, in accordance with the usual procedure” which governs the thorny issue of personal data.
Coinbase's statement follows the release of screenshots showing the firm's internal support interface on Telegram. The captures were published by the Scattered Lapsus Hunters gang, which specializes in data theft and extortion. It is unclear whether this group is behind the internal leak or whether other hackers are responsible. The data may have been recovered or purchased by the criminal group.
This is not the first time that Coinbase has been the victim of a data breach of some of its users. Last spring, its customer support agents, bribed by cybercriminals, had already compromised personal data. Less than 1% of customers were affected. The data made it possible to defraud several investors. Between $180 million and $400 million was stolen in the attacks.
[COLOR=rgb(184, 49, 47)]Coinbase[/COLOR], the New York-based cryptocurrency exchange, announces that it has suffered a new data leak. The incident occurred during the month of December 2025, reports Bleeping Computer.
As the number 2 exchange in the crypto market explains, its security team discovered that a “single Coinbase subcontractor” consulted customer information by abusing its access to the internal support interface. This service provider, in charge of customer support, accessed “inappropriately customer information, which affected a very small number of users”.
The data of only 30 investors is affected. Information accessed includes email address, name, date of birth, phone number, wallet balances and transaction histories.
In addition, data relating to the KYC (Know Your Customer) procedure. Mainly deployed in the financial and banking sectors, the KYC procedure makes it possible to control the identity of users online.Its main aim is to combat illegal activities, in particular money laundering, fraud and the financing of terrorism.Many financial institutions, including cryptocurrency platforms approved by law, require the completion of a KYC form before any transaction.
[HEADING=1]Data in the hands of cybercriminals[/HEADING]
Unsurprisingly, Coinbase took care to fire the person who viewed the data. The New York company indicates that “the person concerned no longer works for Coinbase”. In addition, affected users “were informed last year and benefited from identity theft protection services and other advice.” Finally, Coinbase explains that it “reported this incident to the competent authorities, in accordance with the usual procedure” which governs the thorny issue of personal data.
Coinbase's statement follows the release of screenshots showing the firm's internal support interface on Telegram. The captures were published by the Scattered Lapsus Hunters gang, which specializes in data theft and extortion. It is unclear whether this group is behind the internal leak or whether other hackers are responsible. The data may have been recovered or purchased by the criminal group.
This is not the first time that Coinbase has been the victim of a data breach of some of its users. Last spring, its customer support agents, bribed by cybercriminals, had already compromised personal data. Less than 1% of customers were affected. The data made it possible to defraud several investors. Between $180 million and $400 million was stolen in the attacks.

