Coinbase conscious of knowledge leak months earlier than public disclosure: Report
Key Takeaways
- Coinbase delayed public disclosure of a knowledge breach involving TaskUs till Could, regardless of being conscious since January.
- The breach was linked to a TaskUs worker leaking buyer information in change for bribes.
Share this text
Crypto change Coinbase was conscious of a buyer information leak at its outsourcing associate, TaskUs, as early as January, months earlier than its public disclosure in Could, Reuters reported Monday, citing six individuals with data of the incident.
TaskUs insiders advised Reuters {that a} TaskUs worker in India snapped a photograph of her laptop display along with her private cellphone. In change for bribes, the worker and a suspected confederate are believed to have shared Coinbase buyer information with cybercriminals.
In keeping with a January report from India-based media outlet Monetary Categorical, TaskUs abruptly terminated over 300 workers in Indore as a result of challenge closure and accusations of fraud.
TaskUs confirmed it fired two workers in early 2025 for illegally accessing shopper data.
Whereas the agency didn’t title the shopper, sources confirmed it was Coinbase. TaskUs acknowledged these people had been recruited as half of a bigger, coordinated legal marketing campaign focusing on Coinbase, which additionally affected different service suppliers.
The incident got here to mild after Coinbase initiated a $20 million reward program to establish and prosecute these liable for the incident. The corporate acknowledged that bribed customer support brokers leaked clients’ information, however the breach didn’t compromise passwords, non-public keys, or buyer funds.
In keeping with a Could SEC disclosure, Coinbase projected potential prices of as much as $400 million. The corporate famous that though it had recognized situations of contractors accessing worker information “with no enterprise want” in “earlier months,” it solely acknowledged these occasions as a part of a wider extortion marketing campaign upon receiving an extortion demand on Could 11.
“We minimize ties with the TaskUs personnel concerned and different abroad brokers, and tightened controls,” Coinbase advised Reuters.
In a latest submitting with Maine authorities, Coinbase disclosed that the info leak affected over 69,000 customers. The breach was reportedly undetected from December 2024 till Could 2025.
The corporate is cooperating with the US Division of Justice and different legislation enforcement our bodies to analyze.
TaskUs is likely one of the world’s main international outsourcing firms. It’s headquartered in New Braunfels, Texas.
The corporate offers again workplace and customer support assist, content material moderation, synthetic intelligence, operations assist, and danger and response companies to a number of the world’s most modern firms.
Share this text