By: Isha Das
The U.S. Department of Justice (DOJ) is conducting an investigation into a major data breach at Coinbase, which has been linked to insider facilitation. As sources report, attackers managed to infiltrate Coinbase by bribing third-party contractors and employees in India who had privileged access to the exchange's internal support systems. This breach, disclosed on May 15, affects less than 1% of Coinbase's monthly active users, compromising sensitive data, including names, contact details, identity documents, and partially masked financial information. However, critical infrastructure like private keys and cold wallets remains secure.
The breach resulted in extortion attempts with attackers demanding a $20 million ransom payable in Bitcoin. The CEO of Coinbase, Brian Armstrong, refused to comply, choosing instead to create a $20 million reward fund for information leading to the identification and prosecution of those responsible for the attack. Coinbase is cooperating with federal and international law enforcement agencies to address this security challenge, and its chief legal officer, Paul Grewal, confirmed federal authorities have begun pursuing those involved in the criminal activity.
In assessing the financial aftermath of the breach, Coinbase disclosed in their Form 8-K filing with the U.S. Securities and Exchange Commission (SEC) an estimated cost of $180 million to $400 million for remediation expenses and user reimbursements. ZachXBT, a security researcher, noted significant losses related to phishing and social engineering scams targeting Coinbase customers, further highlighting the exploitation of impersonation tactics to extract sensitive information from users.
The involvement of the DOJ marks a significant escalation in addressing this catastrophic insider-related breach. The ongoing investigation aims not only to bring perpetrators to justice but also to strengthen the industry's security protocols against such penetrating cyber threats. For more detailed information about the security measures taken to protect sensitive customer information, please visit the official Coinbase site.