Inside the $400 million Coinbase breach: An Indian call center and teenage hackers
On May 15, Coinbase revealed that criminals had stolen personal data from tens of thousands of customers—the biggest security incident in the company's history, and one that is poised to cost it as much as $400 million. The breach is notable not only for its scale, but the way the hackers went about it: Bribing overseas customer support agents to share confidential customer records.
Coinbase has responded by publicly announcing it had put a $20 million bounty on those who stole the data, and who sought to blackmail the company so as not to reveal the incident. But it has shared few details about who carried out the attack or how the hackers were able to target its agents so successfully.
A recent investigation by Fortune, including a review of email messages between Coinbase and one of the hackers, has uncovered new details about the incident that strongly suggest a loose network of young English-speaking hackers are partly responsible. Meanwhile, the findings also highlight the role of so-called BPOs, or business process outsourcing units, as a weak link in tech firms' security operations.
The story starts with a small but publicly traded company based in New Braunfels, Texas, called TaskUs. Like other BPOs, it provides customer services to big tech at a low cost by employing staff overseas. In January, TaskUs laid off 226 staff members working for Coinbase from its service center in Indore, India, according to a company spokesperson.
Since 2017, according to a filing with the Securities and Exchange Commission, TaskUs has provided customer service personnel to Coinbase, an arrangement that reaps the U.S. crypto giant significant savings in labor costs. But there's a catch, of course: When customers email to inquire about their accounts or a new Coinbase product, they're likely talking to an overseas TaskUs employee. And because these agents earn low wages compared to workers in the U.S., they've proved susceptible to bribes.
'Early this year we identified two individuals who illegally accessed information from one of our clients,' a TaskUs spokesperson told Fortune, in reference to Coinbase. 'We believe these two individuals were recruited by a much broader, coordinated criminal campaign against this client that also impacted a number of other providers servicing this client.'
The TaskUs firings in January came less than a month after Coinbase discovered theft of customer data, according to a regulatory filing from the company. On Tuesday, a federal class action suit filed in New York on behalf of Coinbase customers accused TaskUs of negligence in protecting customer data. 'While we cannot comment on litigation, we believe these claims are without merit and intend to defend ourselves,' a TaskUs spokesperson said. 'We place the highest priority on safeguarding the data of our clients and their customers and continue to strengthen our global security protocols and training programs.'
A person familiar with the security incident, who asked not to be identified in order to speak candidly, said the hackers had also targeted other BPOs, in some cases successfully, and that the nature of the data stolen varied according to each incident.
This stolen data was not enough for the hackers to break into Coinbase's crypto vaults. But it did provide a wealth of information to help criminals pose as fake Coinbase agents, who contacted customers and persuaded them to hand over their crypto funds. The company says the hackers stole the data of over 69,000 customers, but did not say how many of these had been victims of so-called social engineering scams.
The social engineering scams in this case involved criminals who used the stolen data to impersonate Coinbase employees and persuade victims to transfer their crypto funds.
'As we've already disclosed, we recently discovered that a threat actor had solicited overseas agents to capture customer account information dating back to December of 2024. We notified affected users and regulators, cut ties with the TaskUs personnel involved and other overseas agents, and tightened controls,' said Coinbase in a statement, adding it is reimbursing customers who lost funds in the scams.
Coinbase also stated that the $400 million figure it has cited publicly as the overall cost of the breach is at the top end of its estimates, and that its low-end figure is $180 million.
While social engineering scams that revolve around impersonation of company representatives are hardly new, the scale at which hackers targeted BPOs does appear to be novel. And while no one has definitively identified the perpetrators, a number of clues point strongly to a loosely affiliated network of young English-speaking hackers.
In the days following the disclosure of the Coinbase breach in mid-May, Fortune exchanged messages on Telegram with an individual who called himself 'puffy party' and who claims to be one of the hackers.
Two other security researchers who spoke with the anonymous hacker told Fortune they found the individual to be credible. 'Based on what he shared with me, I took his statements seriously and was unable to find evidence that his statements were false,' said one. Both researchers requested anonymity because they were afraid of receiving subpoenas for speaking with the purported hacker.
In the exchanges, the individual shared numerous screenshots of what they said were emails with Coinbase's security team. The name they used to communicate with the company was 'Lennard Schroeder.' They also shared screenshots of a Coinbase account belonging to a former executive of the company that displayed crypto transactions and extensive personal details.
Coinbase did not deny the authenticity of the screenshots.
The emails shared by the purported hacker include the blackmail threat for $20 million in Bitcoin, which Coinbase refused to pay, and mocking comments about how the hacking group would use some of the proceeds to purchase hair for Brian Armstrong, the company's bald CEO. 'We're willing to sponsor a hair transplant so that he may graciously traverse the world with a fresh set of hair,' wrote the hackers.
In the Telegram messages, the person—whose existence Fortune learned of from a security researcher—expressed contempt for Coinbase.
Many crypto robberies are carried out by Russian criminal gangs or the North Korean military, but the alleged hacker says the job was pulled off by a loose affiliation of teenagers and 20-somethings alternatively called the 'Comm' or 'Com' —shorthand for the Community.
In the last two years, reports of the Comm have bubbled up in media reports about other hacking incidents, including a New York Times story earlier this month in which one of the alleged perpetrators of a series of crypto thefts identified himself as a member of the group. And in 2023, hackers, whom investigators identified as part of the Comm, targeted the online operations of a handful of Las Vegas casinos and tried to extort MGM Resorts for $30 million, according to the Wall Street Journal.
Unlike the Russian and North Korean crypto hackers, who are typically seeking only money, members of the Comm are often motivated by attention seeking or the thrill of mischief as well. They sometimes collaborate on hacking attacks but also compete with each other to see who can steal more.
'They come from video games, and then they bring their high scores into the real world,' said Josh Cooper-Duckett, director of investigations at Cryptoforensic Investigators. 'And their high score in this world is how much money they steal.'
In the Telegram messages, the purported hacker said that members of the Comm specialize in different parts of a heist. The hacker's team bribed the customer support agents and gathered the customer data, which they gave to others outside of their group who are well-versed in carrying out social engineering scams. They added that different Comm-affiliated groups coordinated on social platforms like Telegram and Discord about how to carry out different portions of the operation and agreed to split the proceeds.
Sergio Garcia, founder of the crypto investigations company Tracelon, told Fortune that the hacker's description of the Coinbase exploit mirrors his observations of how the Comm operates and other crypto social engineering scams. The person familiar with the security incidents said those who targeted customers in recent social engineering scams spoke in unaccented North American English.
TaskUs workers in India are paid between $500 and $700 per month, according to a source familiar with the BPO workers' wages. TaskUs declined to comment. Even though that amounts to more than India's gross domestic product per person, the low wages of customer support agents often make them more susceptible to bribes, Garcia told Fortune.
'Obviously that's the weakest point in the chain, because there is an economic reason for them to accept the bribe,' he added.
This story was originally featured on Fortune.com

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
3 hours ago
- Yahoo
How TRUMP Dinner Led To 16,000% Windfall For Investors In An Inspired But Unrelated Memecoin
Benzinga and Yahoo Finance LLC may earn commission or revenue on some items through the links below. Investors in an erstwhile little-known memecoin may be the biggest winners of President Donald Trump's reception of top holders of his memecoin. TRUMP has recorded significant losses in the wake of the controversial dinner. The White House continues to deny that Trump's actions amount to any wrongdoing. After weeks of anticipation and protests, President Donald Trump's dinner with top holders of his Official Trump, or TRUMP, memecoin, has come and gone. Thursday saw Trump wine and dine the top 220 holders of his memecoin and on Friday, he hosted a VIP reception and White House tour for the top 25 holders. However, the dinner and reception have not only benefited Trump's memecoin high rollers. Don't Miss: — no wallets, just price speculation and free paper trading to practice different strategies. Grow your IRA or 401(k) with Crypto – . Investors in Trump Dinner, or DINNER, a memecoin on Base, the Coinbase-incubated (NASDAQ:COIN) Ethereum Layer 2, have seen a massive windfall, at least one paper, from the attention the event has received. Even though the token is affiliated with the Trump dinner in name only, it soared as much as 16,000% between Thursday and Friday from a market cap of barely $2 million to $325 million. At last look, the token has yet to lose momentum. It is up over 950% in the past 24 hours and now boasts a $380 million market cap. It remains to be seen how long it will be able to sustain this rally as attention surrounding the event cools. While the controversial dinner has been a boon for this erstwhile little-known memecoin, it was a 'sell the news event' for the Trump memecoin. Trending: New to crypto? on Coinbase. Between Thursday and Friday, the token fell as much as 14%. One reason for this dump is that the high rollers dumped en masse after securing an audience with Trump. 'The TRUMP dinner was full of jeets,' on-chain sleuth 'dethective,' said Friday on X. 'Almost 1 in 2 people who attended was holding 0 tokens.' Specifically, the analyst found that 92 wallets, accounting for about 41% of the dinner invitees, had dumped all their tokens. They sold 4.3 million TRUMP tokens, worth over $54 million at current prices in total. This move should perhaps come as no surprise as the memecoin was in free fall before the announcement detailing a chance for top holders to secure an audience with Trump. And even the bump triggered by that announcement failed to make a dent in its woeful record. At last look, the token is trading at $12.65, down 84% from its highs of nearly $80 in January. As reported earlier this month, nearly half of the wallets holding TRUMP are in the red. This, however, has not stopped CIC Digital LLC and Fight Fight Fight, the two Trump-owned firms behind the memecoin from raking in over $300 million from trading fees since January. The Trump administration continues to deny that the president's involvement in the cryptocurrency space amounts to any wrongdoing. 'It's absurd for anyone to insinuate that this president is profiting off of the presidency,' White House press secretary Karoline Leavitt said Thursday during a press conference. 'This president was incredibly successful before giving it all up to serve our country publicly.' Read Next: A must-have for all crypto enthusiasts: . 'Scrolling To UBI' — Deloitte's #1 fastest-growing software company allows users to earn money on their phones. Image: Shutterstock Send To MSN: 0 This article How TRUMP Dinner Led To 16,000% Windfall For Investors In An Inspired But Unrelated Memecoin originally appeared on Sign in to access your portfolio

Yahoo
5 hours ago
- Yahoo
Making the Grade: Sauk Valley-area students obtain career endorsements, plan futures through Pathways program
May 30—STERLING — More than 40 high school graduates from across the Sauk Valley took advantage of a program this year that helped prepare them for careers in the education sector. Created under the state's 2016 Postsecondary and Workforce Readiness Act, the Illinois College & Career Pathway Endorsement Program allows students to earn a formal endorsement on their high school diploma or transcript by completing a series of structured requirements designed to prepare them for life after high school in their chosen career path. Students choose from one of seven career pathways: * Agriculture food and natural resources * Health sciences and technology * Finance and business services * Arts and communications * Information technology * Human and public services * Manufacturing, engineering, technology and trades According to the PWR Act, to qualify for the endorsement, students must complete the following requirements: * Students must complete an individualized learning plan that outlines their college pathway and relates to their career goals and plans for financial aid. They also must include a resume and a personal statement. * Complete at least two career exploration activities or one intensive experience before graduating. This can include completing a career-interest survey, attending a career fair, interviewing someone from their chosen career field, participating in a college visit and job shadowing or visiting a local business. * Complete at least two team-based projects with adult mentoring that focuses on solving a problem related to their chosen career field. * Complete 60 cumulative hours in a paid or for-credit, supervised career development experience, concluding with an evaluation of their professional skills. This can be completed at any point throughout their four years of high school, including during the summer. * Complete two years of high school coursework, or demonstrate equivalent competencies, leading toward a postsecondary credential with recognized labor market value. This includes a minimum of six hours of early college credit that can be earned by taking dual-credit classes, Advanced Placement classes or college classes. * Demonstrate college-ready proficiency in English and math by graduation. This can be done in one of several ways, including earning the required scores on the ACT, SAT, or college placement tests; achieving the required grade-point average set by their local community college, or receiving a grade of "C" or higher in transitional English and math classes. Anji Garza is the director of Professional Learning and Educational Services for Regional Office of Education No. 47 in Sterling. She said students who earn an endorsement enter college better prepared and more confident in their chosen career paths, having already explored their interests through real-world experience. "This allows students to explore their options much more intentionally, as opposed to students who go and maybe don't have that career in mind, and then they're exploring those options in college, which we know can be a very expensive career exploration endeavor," Garza said. Students with an endorsement also earn a $100 credit at Dixon's Sauk Valley Community College. In 2021, SVCC — in partnership with ROE 47 — was awarded a $249,000 grant from the Illinois State Board of Education to support career pathways for high school students. It was the first phase of a four-part grant cycle totaling $747,000. SVCC's Peer Academic Support Services Facilitator Celina Benson said the CCPE program offers students exposure to careers in their chosen field they might not have previously considered. "When you think about health sciences, the first thing you think of is a doctor or a nurse, but there's so many other careers within that sector," Benson said. "Whether it's rad tech or sonography, they might not have been exposed to some of that information. With this program, they get to see it firsthand within those careers." Additionally, students who earn their endorsement in the education pathway are advanced to the final round for the Golden Apple Scholarship, which provides the winners with four years of free college tuition and fees. In 2022, Gov. JB Pritzker signed Public Act 102-0917, which requires all Illinois high school districts to begin offering College and Career Pathway Endorsements. Starting with the Class of 2027, districts must apply to the state to offer at least one endorsement area — either on their own, through a career center, or in partnership with other districts. By 2029, they must add a second endorsement, and by 2031, districts with more than 350 high school students must offer a third. ROE 47 Digital Teaching & Learning Specialist Stacey Dinges said 18 school districts throughout the Sauk Valley currently offer at least one pathway endorsement. Participating school districts include: * Riverbend Community Unit School Dist 2 * Dixon Public Schools 170 * Rock Falls High School 301 * Morrison Community Unit School Dist 6 * Amboy Community Unit School District 272 * Ashton-Franklin Center CUSD 275 * Forrestville Valley CUSD 221 * Regional Safe School Center for Change * Prophetstown-Lyndon-Tampico 3 * Byron CUSD 226 * Rock Falls Elementary District 13 * Sterling District 5 * Whiteside Area Career Center * Ohio CCSD 17 * Rochelle Township High School * Oregon Community Unit School District 220 * Polo Community Unit School District * Chadwick-Milledgeville CUSD 399 * Eastland CUSD 308 As of July 1, 2025, all districts must either apply to offer the required number of endorsement areas or have a board-approved plan in place to meet the deadlines. Districts also have the option to opt out by passing a formal resolution through their school board. "Each school does it a little differently," Dinges said. "Some students use their community colleges, some districts use their Career Center, and some do it all in-house. It just depends on the district." For more information, call ROE 47 at 815-625-1495 or visit
Yahoo
6 hours ago
- Yahoo
Missing Bronx girl, 4, found after search by NYPD
BRONX, N.Y. (PIX11) – The NYPD was looking for a 4-year-old girl from the Bronx. The child was last seen on Friday at 3:20 PM, near East 167 Street and Third Avenue in the Bronx. Authorities said she was last seen wearing gray pants and a gray shirt. More Local News According to an NYPD social media post, the girl was last seen with a woman with red hair who was wearing blue jeans, a black shirt, and white shoes. She was later found, police said. Submit tips to police by calling Crime Stoppers at 1-800-577-TIPS (8477), visiting downloading the NYPD Crime Stoppers mobile app, or texting 274637 (CRIMES) then entering TIP577. Spanish-speaking callers are asked to dial 1-888-57-PISTA (74782). Matthew Euzarraga is a multimedia journalist from El Paso, Texas. He has covered local news and LGBTQIA topics in the New York City Metro area since 2021. He joined the PIX11 Digital team in 2023. You can see more of his work here. Copyright 2025 Nexstar Media, Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.