Skip to content

Coinbase Cartel

Coinbase Cartel is a cyber-extortion group that emerged around September 2025 and is primarily associated with data-theft and leak-site extortion rather than disruptive file encryption.

Profile source: Mallory opens in a new tab

Coinbase Cartel

Family profile

Coinbase Cartel is a cyber-extortion group that emerged around September 2025 and is primarily associated with data-theft and leak-site extortion rather than disruptive file encryption. The group presents itself as an exfiltration-first operation and has been described as rejecting the traditional ransomware label even though it is commonly tracked within the ransomware ecosystem. Its activity has included public victim naming, staged disclosure of stolen data, and pressure tactics centered on reputational and commercial harm instead of widespread system unavailability.

The group has claimed victims across multiple regions, including organizations in the United States, South Korea, and Europe, and has shown a notable interest in technology-oriented targets and developer environments. Reported operations include extortion following compromise of source-code repositories and publication threats involving stolen code. This tradecraft aligns with broader intrusion patterns seen in English-speaking cybercriminal ecosystems that emphasize credential theft, social engineering, cloud and SaaS abuse, and compromise of identity and collaboration platforms.

Coinbase Cartel is widely characterized as a data-exfiltration-only or data-exfiltration-first extortion actor. Public reporting indicates that it often steals data while leaving victim systems operational, using leak-site workflows and victim-status staging to increase coercive pressure over time. The group has been linked by some researchers to the broader ecosystem associated with ShinyHunters, Scattered Spider, and Lapsus$, which are known for social engineering, use of stolen credentials, cloud-centric intrusion paths, and attacks against technology companies; however, specific organizational relationships and command structure are not fully established at high confidence.

The actor has also been referenced under the alias Storm-2981. Available reporting does not provide high-confidence evidence of nation-state sponsorship. Coinbase Cartel should be understood as a financially motivated extortion actor operating in the modern leak-site economy, where rapid data theft, public shaming, and selective disclosure can substitute for traditional ransomware encryption.

Operational record

1
YARA rules
1
Leak sites
0 available

Recent claims

MITRE ATT&CK

Coinbase Cartel in ATT&CK

22 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.