
Cryptocurrency exchange giant Coinbase has reported its most significant data breach to date, impacting over 69,000 customers and potentially costing the company as much as $400 million. The breach, revealed in a recent Fortune investigation, is believed to have originated from a bribery scheme involving Indian customer support agents employed by a U.S.-based outsourcing firm.
Hackers allegedly targeted TaskUs, a prominent outsourcing company headquartered in the United States with extensive operations in Indore, India. Since 2017, TaskUs has been responsible for handling Coinbase’s customer service functions. According to reports, hackers successfully bribed several Indian-based agents to leak sensitive customer data, exploiting the relatively low wages of call center employees who typically earn between $500 and $700 per month.
In January, weeks after the data breach came to light, TaskUs terminated more than 200 employees associated with the Coinbase account. Coinbase has since cut ties with the individuals involved and any other personnel suspected of complicity in the breach.
Security experts have identified the vulnerability in outsourced customer support systems as a critical weakness. “Obviously that’s the weakest point in the chain, because there is an economic reason for them to accept the bribe,” said Sergio Garcia, founder of Tracelon, a firm specializing in cryptocurrency investigations.
Although the breach did not grant hackers access to Coinbase’s internal crypto vaults, the stolen customer information was reportedly used to impersonate company staff. This allowed attackers to deceive customers into divulging login credentials and other sensitive data, leading to unauthorized access to individual cryptocurrency accounts and financial losses.
Coinbase has confirmed that it is reimbursing affected customers, though it has not publicly disclosed the number of users impacted by these scams. The company has also stated that it is conducting a thorough review of its security practices in the wake of the breach.
In response to the incident, a class-action lawsuit has been filed in New York, accusing TaskUs of negligence in safeguarding customer data. TaskUs has denied any wrongdoing and maintains that it is reinforcing its internal security systems. The company suspects the breach may be part of a wider cybercrime operation targeting multiple Coinbase-linked service providers.
The hackers behind the operation are believed to be members of an online collective known as “the Comm” or “Community.” This group consists largely of young, English-speaking cybercriminals who coordinate via messaging platforms such as Telegram and Discord. Unlike more traditional and structured hacking groups operating from countries like Russia or North Korea, the Comm is described as loosely organized and driven by status-seeking behaviors.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543