Skip to main content
Back to overview
Medium

Coinbase Confirms Insider Breach Linked to Leaked Support Tool Screenshots

Coinbase confirms insider breach linked to leaked support tool screenshots Coinbase has confirmed an insider breach after a contractor improperly accessed the data of approximately thirty customers, which…

Key points

  • Insider breach involving a contractor.
  • Approximately 30 customers affected.
  • Contractor improperly accessed customer information.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Feb 3, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

CoinbaseData DisclosureLeaked Support Tool Screenshots CoinbaseCoinbaseBleepingComputerLastCoinbase. ImpactedTaskUsScattered Lapsus HuntersSLH

Quick context

Questions about this signal

What happened in this signal?

Coinbase confirms insider breach linked to leaked support tool screenshots Coinbase has confirmed an insider breach after a contractor improperly accessed the data of approximately thirty customers, which BleepingComputer has learned is a new incident that occurred in December. "Last year our security team detected that a single Coinbase contractor improperly accessed customer information, impacting a very small number of users (approximately 30)," a Coinbase spokesperson told BleepingComputer. "The individual no longer performs services for Coinbase. Impacted users we notified last year and were provided with identity theft protection services and other guidance. We have also disclosed this incident to the relevant regulators, as is standard practice." BleepingComputer has learned that this is a newly revealed insider breach and is not related to the previously disclosed TaskUs insider breach in January 2025. This statement comes after threat actors known as "Scattered Lapsus Hunters" (SLH) briefly posted screenshots of an internal Coinbase support interface on Telegram and then deleted the posts soon after. The screenshots showed a support panel that gave access to customer information, including email addresses, names, date of birth, phone numbers, KYC information, cryptocurrency wallet balances, and transactions. It is not uncommon for screenshots and stolen data to be passed around among different threat actors before being leaked or disclosed, so it is unclear whether this group was behind the insider breach or whether other threat actors carried it out. However, the same threat actors previously claimed to have bribed an insider at CrowdStrike to share screenshots of internal applications. Over the past few years, Business Process Outsourcing (BPO) companies have become increasingly targeted by threat actors seeking access to customer data, internal tools, or corporate networks. A Business Process Outsourcing (BPO) company is a third-party firm that performs operational tasks for another organization. These tasks commonly include customer support, identity verification, IT help desk services, and account management. Because BPO employees often have access to sensitive internal systems and customer information, they have become a high-value target for attackers. In the past year, threat actors have exploited BPOs through bribing insiders with legitimate access, social engineering support staff to grant unauthorized access, and compromising BPO employee accounts to reach internal systems. As we have seen with Coinbase this year, one way BPOs are targeted is by bribing their employees to steal or share customer information. Coinbase  disclosed a similar data breach last year, later linked to external customer support representatives employed by TaskUs, an outsourcing firm that provides services to the crypto exchange. Another common tactic is social engineering attacks against outsourced IT and support desks, where threat actors impersonate employees and call BPO help lines to obtain access to internal corporate systems. In one of the most prominent cases, attackers posed as an employee and convinced a Cognizant help desk support agent to grant them access to a Clorox employee account, allowing them to breach the company's network. The incident later became the focus of a $380 million lawsuit by Clorox against Cognizant. Google also reported that threat actors targeted U.S. insurance firms in social engineering attacks on outsourced help desks to gain access to internal systems. Retailers also confirmed that social engineering attacks against support personnel enabled ransomware and data theft attacks. Marks & Spencer confirmed attackers used social engineering to breach its networks , while Co-op disclosed data theft following a ransomware attack that similarly abused support staff access. In response to the attacks on M&S and Co-op retail companies, the  U.K. government issued guidance on social engineering attacks against help desks and BPOs. In some cases, hackers target the BPO employee accounts themselves to gain access to the customer data they manage. In October, Discord disclosed a data breach that allegedly exposed data from 5.5 million unique users after its Zendesk support system instance was compromised. While the company did not confirm how its instance was breached, the threat actors told BleepingComputer that they used a compromised account belonging to a support agent employed by an outsourced business process outsourcing (BPO) provider. Using this account, they downloaded Discord's customer data.

When was this signal reported?

Shadow Tier lists Feb 3, 2026 as the signal date.

Which organization is connected to this signal?

Coinbase is the organization connected to this public signal.

Explore Coinbase
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence