Supply chain
β Supply Chain
Coinbase Third-Party Breach (June 2025)
Primary Source βIncident Details
Coinbase breach tied to bribed TaskUs support agents in India. A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange. According to Reuters, who spoke to numerous TaskUs employees, the data breach was first discovered in January after a TaskUs employee was caught capturing photos of her computer screen using a personal device. Reportedly, the incident was witnessed by multiple TaskUs employees, and during the subsequent investigations, two admitted they were funneling sensitive Coinbase user data to external hackers in exchange for bribes. Third-party company: TaskUs.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- TaskUs
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-06-01 Breach occurred
- 2025-06-03 Publicly disclosed