Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Molly White
Molly White
@molly0xfff@hachyderm.io  ·  activity timestamp 8 months ago

A Coinbase data breach filing with the Maine Attorney General finally gives us some more detail than Coinbase’s vague “less than 1% of monthly transacting users”. 69,461 people were affected, and Coinbase says the data breach occurred on December 26, 2024.

https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/f61fae18-f669-499e-9a87-f4d323d281f8.html

It took them almost five months between the incident and the incident disclosure, although the company has since admitted it knew customer support agents were suspiciously accessing customer data as far back as January.

#coinbase #crypto #cryptocurrency

Data Breach Notifications
Entity Information
Type of Organization: Financial Services
Entity Name: Coinbase, Inc.
Street Address: 248 3rd Street #434
City: Oakland
State, or Country if outside the US: CA
Zip Code: 94607
Submitted By
Name: Michael Rubin
Title: Attorney
Firm name (if different than entity): Latham and Watkins LLP
Telephone Number: (415) 395-8154
Email Address: michael.rubin@lw.com
Relationship to entity whose information was compromised: Outside Counsel
Breach Information
Total number of persons affected (including residents): 69461
Total number of Maine residents affected: Approximately 217
If the number of Maine residents exceeds 1,000, have the consumer reporting agencies been notified:
Date(s) Breach Occured: December 26, 2024
Date Breach Discovered: May 11, 2025
Description of the Breach:
Insider wrongdoing
Information Acquired - Name or other personal identifier in combination with:
Notification and Protection Services
Type of Notification: Written
Date(s) of consumer notification: May 30, 2025
Copy of notice to affected Maine residents: Appendix_A_-_Coinbase_Template_Individual_Notification_Letter.pdf
Date of any previous (within 12 months) breach notifications: 07/16/2024
Were identity theft protection services offered: Yes
If yes, please provide the duration, the provider of the service and a brief description of the service: We are offering all impacted
Data Breach Notifications Entity Information Type of Organization: Financial Services Entity Name: Coinbase, Inc. Street Address: 248 3rd Street #434 City: Oakland State, or Country if outside the US: CA Zip Code: 94607 Submitted By Name: Michael Rubin Title: Attorney Firm name (if different than entity): Latham and Watkins LLP Telephone Number: (415) 395-8154 Email Address: michael.rubin@lw.com Relationship to entity whose information was compromised: Outside Counsel Breach Information Total number of persons affected (including residents): 69461 Total number of Maine residents affected: Approximately 217 If the number of Maine residents exceeds 1,000, have the consumer reporting agencies been notified: Date(s) Breach Occured: December 26, 2024 Date Breach Discovered: May 11, 2025 Description of the Breach: Insider wrongdoing Information Acquired - Name or other personal identifier in combination with: Notification and Protection Services Type of Notification: Written Date(s) of consumer notification: May 30, 2025 Copy of notice to affected Maine residents: Appendix_A_-_Coinbase_Template_Individual_Notification_Letter.pdf Date of any previous (within 12 months) breach notifications: 07/16/2024 Were identity theft protection services offered: Yes If yes, please provide the duration, the provider of the service and a brief description of the service: We are offering all impacted
Data Breach Notifications Entity Information Type of Organization: Financial Services Entity Name: Coinbase, Inc. Street Address: 248 3rd Street #434 City: Oakland State, or Country if outside the US: CA Zip Code: 94607 Submitted By Name: Michael Rubin Title: Attorney Firm name (if different than entity): Latham and Watkins LLP Telephone Number: (415) 395-8154 Email Address: michael.rubin@lw.com Relationship to entity whose information was compromised: Outside Counsel Breach Information Total number of persons affected (including residents): 69461 Total number of Maine residents affected: Approximately 217 If the number of Maine residents exceeds 1,000, have the consumer reporting agencies been notified: Date(s) Breach Occured: December 26, 2024 Date Breach Discovered: May 11, 2025 Description of the Breach: Insider wrongdoing Information Acquired - Name or other personal identifier in combination with: Notification and Protection Services Type of Notification: Written Date(s) of consumer notification: May 30, 2025 Copy of notice to affected Maine residents: Appendix_A_-_Coinbase_Template_Individual_Notification_Letter.pdf Date of any previous (within 12 months) breach notifications: 07/16/2024 Were identity theft protection services offered: Yes If yes, please provide the duration, the provider of the service and a brief description of the service: We are offering all impacted

Office of the Maine AG: Consumer Protection: Privacy, Identity Theft and Data Security Breaches

  • Copy link
  • Flag this post
  • Block
Molly White
Molly White
@molly0xfff@hachyderm.io replied  ·  activity timestamp 8 months ago

SEC requires material cybersecurity incidents be disclosed within four business days; state laws often have a 30-day disclosure deadline. It’s not clear if customers outside the US were affected; if so, other disclosure laws may apply.

#coinbase #crypto #cryptocurrency

  • Copy link
  • Flag this comment
  • Block
Molly White
Molly White
@molly0xfff@hachyderm.io replied  ·  activity timestamp 8 months ago

Security researchers who have spent months trying to call Coinbase’s attention to serious issues at the company are disputing Coinbase’s claims about the timing of the breach. “Threat actors had ongoing access via multiple insiders over a prolonged period of time.”

2 media
Oh good apparently now the Coinbase breach happened on Dec 26, 2024. LOL So since Coinbase won't be straight with you, I will. Threat actors had ongoing access via multiple insiders over a prolonged period of time. (Screenshot of Maine AG notification)
Oh good apparently now the Coinbase breach happened on Dec 26, 2024. LOL So since Coinbase won't be straight with you, I will. Threat actors had ongoing access via multiple insiders over a prolonged period of time. (Screenshot of Maine AG notification)
Oh good apparently now the Coinbase breach happened on Dec 26, 2024. LOL So since Coinbase won't be straight with you, I will. Threat actors had ongoing access via multiple insiders over a prolonged period of time. (Screenshot of Maine AG notification)
As evidence, here's a very small cutout of one high value customer's Coinbase account.

This wasn't pulled on Dec 26, 2024 honey.

(Screenshot showing dates between 2025-02-07 and 2025-02-10)
As evidence, here's a very small cutout of one high value customer's Coinbase account. This wasn't pulled on Dec 26, 2024 honey. (Screenshot showing dates between 2025-02-07 and 2025-02-10)
As evidence, here's a very small cutout of one high value customer's Coinbase account. This wasn't pulled on Dec 26, 2024 honey. (Screenshot showing dates between 2025-02-07 and 2025-02-10)
  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct