Report Says Coinbase Knew of Data Leak Months Before Breach Tied to $400 Million Cost

Report Says Coinbase Knew of Data Leak Months Before Breach Tied to $400 Million Cost

N
News Editor 01
2026-07-08 22:44:24
Reuters reported that Coinbase was alerted months before publicly disclosing a customer data leak linked to outsourcing partner TaskUs. The incident may cost the exchange up to $400 million and has intensified scrutiny of data security in crypto.
Coinbasedata breachTaskUsexchange securityuser privacy

Coinbase was reportedly informed about a customer data leak at outsourcing partner TaskUs roughly four months before it publicly acknowledged a breach that may cost the company as much as $400 million. The report, published by Reuters and based on six sources, adds new detail to a security incident that has already raised serious questions about how major crypto platforms manage customer data, third-party vendors, and internal support access.

TaskUs Incident Reportedly Triggered Early Internal Alarm

According to the report, one of the key incidents took place in Indore, India, where a TaskUs employee was allegedly caught taking photos of her work computer screen. The matter was reportedly escalated to Coinbase. Five anonymous former employees cited in the report said the woman and an alleged accomplice were believed to have passed customer information to hackers in exchange for bribes.

An investigation was launched after the incident surfaced. Soon afterward, around 200 TaskUs employees were abruptly dismissed, leading to complaints from affected workers who claimed unfair termination. While the full scope of the internal inquiry was not detailed, the reported firings suggest the matter was treated as a serious operational and compliance issue.

Public Disclosure Came After an Extortion Attempt

Despite reportedly learning months earlier that contractors had improperly obtained user data, Coinbase did not publicly confirm the breach until May 15. The disclosure came after hackers who allegedly possessed sensitive customer information attempted to extort $20 million from the exchange.

At the time, Coinbase said the attackers had targeted internal customer support systems and gained access to personal information belonging to fewer than 1% of monthly transacting users. The company framed the event as a limited but serious compromise involving support-related systems rather than a direct breach of customer funds. Even so, the latest reporting may fuel criticism over the delay between the company’s early awareness of suspicious activity and its eventual public response.

Why the Incident Matters Beyond the Financial Estimate

The reported $400 million cost has drawn attention on its own, but the broader concern may be even more significant. The breach comes at a time when wealthy crypto holders have increasingly been targeted by violent criminals, including kidnappers and extortionists. In several high-profile cases, attackers appeared to have detailed knowledge of victims’ identities and holdings, raising fears that leaked customer data can translate into real-world physical danger.

That context makes this incident especially sensitive. If personal data, account-linked information, or support records can be accessed through outsourced service channels, the consequences may extend well beyond regulatory penalties, remediation expenses, and reputational damage. For crypto users, the issue is not only whether their assets remain secure on-platform, but also whether their identity and wealth exposure can be inferred through leaked support data.

Coinbase and TaskUs Responses

Coinbase said it had become aware in prior months that contractors had improperly obtained user data, but the company said it intensified its response after the extortion attempt. The exchange added that it had cut ties with the TaskUs personnel involved, ended relationships with other overseas agents connected to the case, and tightened internal controls.

TaskUs, for its part, said the two employees at the center of the incident were terminated in January. The company’s response indicates that action was taken internally, though the Reuters account has amplified scrutiny over whether vendor-side safeguards and client oversight were sufficient to prevent customer data from being mishandled in the first place.

A Broader Warning for the Crypto Industry

The Coinbase-TaskUs episode underscores a growing challenge for large crypto exchanges operating global support networks: every outsourced workflow can become a potential point of failure if access controls, monitoring, and data segmentation are not strong enough. Customer support teams often handle highly sensitive identity information, and any weakness in those systems can become disproportionately dangerous in the crypto sector, where financial incentives for attackers are unusually high.

As exchanges scale internationally, investors and regulators are likely to focus more closely on vendor governance, employee surveillance policies, least-privilege access frameworks, and breach disclosure timelines. In that sense, this case is not just about one company’s losses. It is also a reminder that in crypto, data security is inseparable from user safety, platform trust, and long-term industry credibility.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.