Coinbase Cartel
Coinbase Cartel is a cyber-extortion group that emerged around September 2025 and is primarily associated with data-theft and leak-site extortion rather than disruptive file encryption.
Profile source: Mallory opens in a new tabCoinbase Cartel
Family profile
Coinbase Cartel is a cyber-extortion group that emerged around September 2025 and is primarily associated with data-theft and leak-site extortion rather than disruptive file encryption. The group presents itself as an exfiltration-first operation and has been described as rejecting the traditional ransomware label even though it is commonly tracked within the ransomware ecosystem. Its activity has included public victim naming, staged disclosure of stolen data, and pressure tactics centered on reputational and commercial harm instead of widespread system unavailability.
The group has claimed victims across multiple regions, including organizations in the United States, South Korea, and Europe, and has shown a notable interest in technology-oriented targets and developer environments. Reported operations include extortion following compromise of source-code repositories and publication threats involving stolen code. This tradecraft aligns with broader intrusion patterns seen in English-speaking cybercriminal ecosystems that emphasize credential theft, social engineering, cloud and SaaS abuse, and compromise of identity and collaboration platforms.
Coinbase Cartel is widely characterized as a data-exfiltration-only or data-exfiltration-first extortion actor. Public reporting indicates that it often steals data while leaving victim systems operational, using leak-site workflows and victim-status staging to increase coercive pressure over time. The group has been linked by some researchers to the broader ecosystem associated with ShinyHunters, Scattered Spider, and Lapsus$, which are known for social engineering, use of stolen credentials, cloud-centric intrusion paths, and attacks against technology companies; however, specific organizational relationships and command structure are not fully established at high confidence.
The actor has also been referenced under the alias Storm-2981. Available reporting does not provide high-confidence evidence of nation-state sponsorship. Coinbase Cartel should be understood as a financially motivated extortion actor operating in the modern leak-site economy, where rapid data theft, public shaming, and selective disclosure can substitute for traditional ransomware encryption.
Operational record
Recent claims
MITRE ATT&CK