Skip to content
NetarxImpact Database
Smishing (SMS)No AI reportedConfirmed

Coinbase employee phished by SMS then talked through by a fake IT caller

Coinbase · Cryptocurrency · United States · February 5, 2023

What happened

In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.

How the deception worked

The lure was a text claiming the employee needed to sign in immediately to receive an important message, pointing at a credential-capture page. With a valid password but no second factor, the attacker escalated to a phone call, presenting themselves as internal IT and asking the employee to log into their workstation and follow instructions, which is the standard escalation pattern for this actor. The requests grew progressively more unusual as the call went on. Detection came from behavioural alerting on unusual account activity rather than from the employee, and an internal messaging outreach broke the attacker's hold before meaningful access was established.

AI involvement · No AI reported

Coinbase described a live human caller impersonating corporate IT; no synthetic voice was reported.

The control that would have caught it· our reading, not a claim from the sources

Blocking employee installation of unsanctioned remote-access tools and training staff that IT will never call to ask for MFA codes or screen control converts a credential phish into a contained event.

Sources (3)

  1. Social Engineering - A Coinbase Case Study
    Coinbase·coinbase.comOpen ↗
  2. Coinbase cyberattack targeted employees with fake SMS alert
    BleepingComputer·bleepingcomputer.comOpen ↗
  3. Coinbase breached by social engineers, employee data stolen
    Sophos News·news.sophos.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.