{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:14:33.838Z","total":3,"returned":3,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Bribed overseas support agents leaked Coinbase data; $20M extortion refused","date":"2025-05-15","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in Coinbase's disclosure.","outcomes":["Data Breach","Extortion","Insider Access","Cryptocurrency Theft","Identity Theft"],"loss_usd":null,"loss_note":"Coinbase refused the $20 million demand and instead established a $20 million reward fund for information leading to arrests. Aggregate customer losses from the resulting social engineering were not quantified in the disclosure.","records_affected":69461,"threat_actor":"Unattributed extortion group","summary":"Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.","how_it_worked":"The attackers recruited rather than intruded, paying overseas support agents who already had legitimate access to customer records. Those agents pulled names, addresses, phone numbers, email addresses, masked Social Security digits, masked bank account numbers, government ID images, and account balance and transaction snapshots. Passwords, seed phrases, 2FA codes and private keys were never exposed, so the data alone could not move funds; its value was in making the second stage convincing. Armed with a customer's real balance and transaction history, callers impersonating Coinbase support could establish credibility instantly and talk victims into sending crypto to attacker wallets. Coinbase began seeing unusual support-representative activity in January 2025 and fired the implicated insiders.","lessons":"Support tooling should mask or withhold balance and transaction data by default, with per-record access justification and volume alerting, so a bribed agent cannot assemble the dossier that makes downstream impersonation work.","confidence":"Confirmed","sources":[{"title":"Protecting Our Customers - Standing Up to Extortionists","url":"https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists","publisher":"Coinbase"},{"title":"Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails","url":"https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html","publisher":"The Hacker News"},{"title":"Coinbase confirms insiders handed over data of 70K users","url":"https://www.theregister.com/2025/05/21/coinbase_confirms_insider_breach_affects/","publisher":"The Register"}],"entry_type":"incident","slug":"2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse"},{"title":"Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds","date":"2022-04-03","date_precision":"day","victim_org":"SatoshiLabs (Trezor), via email provider Mailchimp","sector":"Cryptocurrency","country":"Czech Republic","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Data Breach","Credential Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Neither Trezor nor Mailchimp published a loss figure, and Trezor said at the time it was unclear whether any funds were successfully stolen. The '106,856 customers' figure that circulated came from the phishing email itself and was attacker-authored text, not a confirmed breach count.","records_affected":null,"threat_actor":"Unattributed actor targeting cryptocurrency-sector Mailchimp tenants","summary":"Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.","how_it_worked":"The deception happened two steps upstream of the victims. Mailchimp employees were socially engineered into giving attackers access to an internal support and account-administration tool, which let the attackers view and export subscriber lists across tenant accounts and specifically target crypto companies. Holding Trezor's real newsletter list, the attackers sent a security-alert email that borrowed Trezor's own incident-response voice, from the plausible domain trezor.us. Recipients who followed the link reached a cloned Trezor Suite with working-looking functionality that asked for the recovery seed, the one secret that grants irreversible control of a hardware wallet.","lessons":"Hardware wallet vendors should state unconditionally that no update or support flow ever asks for a seed phrase, and email service providers need step-up controls and anomaly detection on internal tools that can export any tenant's subscriber list.","confidence":"Confirmed","sources":[{"title":"Ongoing phishing attacks on Trezor users","url":"https://blog.trezor.io/ongoing-phishing-attacks-on-trezor-users-edd840b17304","publisher":"Trezor (SatoshiLabs)"},{"title":"Mailchimp Insider Targets Trezor Crypto Wallets in Phishing Scam","url":"https://decrypt.co/96942/mailchimp-insider-targets-trezor-crypto-wallets-phishing-scam","publisher":"Decrypt"}],"entry_type":"incident","slug":"2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet"},{"title":"Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash","date":"2020-11-13","date_precision":"day","victim_org":"GoDaddy (registrar); Liquid.com and NiceHash","sector":"Cryptocurrency","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No voice cloning was reported; the callers used conventional pretexting against registrar staff.","outcomes":["Data Breach","Credential Theft","Service Disruption"],"loss_usd":null,"loss_note":"No customer funds were reported lost. Liquid said customer funds remained secure; NiceHash said no emails, passwords or personal data were compromised.","records_affected":null,"threat_actor":"Unattributed","summary":"Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.","how_it_worked":"The attackers called GoDaddy employees and pretended to be authorised parties with a routine domain administration need, a pretext the registrar's own staff were positioned to fulfil. Once a rep made the change, the attackers held registrar-level control of the target's domain and could repoint DNS at will. For Liquid, control of the domain's MX and name server records let them take over internal email accounts, which in turn exposed customer names, addresses, encrypted passwords and identity verification documents. NiceHash saw the same DNS manipulation but reported no data compromise. The exchanges' own security was never touched; the failure was one level up, at the registrar.","lessons":"Registry lock on critical domains, which requires manual out-of-band verification before any DNS or nameserver change, defeats registrar-side social engineering outright.","confidence":"Confirmed","sources":[{"title":"GoDaddy Employees Tricked into Compromising Cryptocurrency Sites","url":"https://threatpost.com/godaddy-employees-tricked-compromise-cryptocurrency/161520/","publisher":"Threatpost"},{"title":"GoDaddy Employees Tricked Into Transferring Control of Crypto Firm Domains: Report","url":"https://www.coindesk.com/markets/2020/11/22/godaddy-employees-tricked-into-transferring-control-of-crypto-firm-domains-report","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic"}]}