In May 2025, Coinbase faced a security breach that didn’t begin with malware or stolen credentials. It started with a bribe. Hackers paid overseas contractors to leak customer data. The attackers didn’t need to break through a firewall—they went around it. The breach affected less than 1% of Coinbase’s users, but the fallout could reach $400 million.
In my experience, this isn’t unusual. What makes insider threats so dangerous is how invisible they are—until they’re not. The story is a sharp reminder: your biggest risk may already have access.
What Happened?
According to CNBC, the attackers approached external customer support agents—contracted employees working outside Coinbase. These agents were bribed to hand over internal tools access and user data, including:
Names and email addresses
Phone numbers
Government ID images
Partial Social Security numbers
The attackers then used that data to run highly targeted scams, tricking users into thinking they were dealing with Coinbase. Crypto transfers followed. Losses mounted.
Coinbase received a $20 million ransom demand, which it refused. CEO Brian Armstrong instead offered a $20 million bounty for information leading to the attackers’ arrest. That move—bold, transparent, and values-driven—stood out to many of us in the industry.

How Did It Happen?
The failure here wasn’t technical. Coinbase had identity controls, multi-factor authentication, and detection tools. What failed was behavioral awareness—especially in roles with privileged but distributed access.
In my work, I see this pattern all the time: a contractor or third-party with legitimate credentials gets socially engineered. These aren’t malicious insiders in the traditional sense. They’re everyday people, working quickly, trying to help, and unaware that they’re being manipulated.
The Hacker News confirmed the agents were not Coinbase employees, but part of a vendor’s support team. That detail is important. Most organizations don’t treat vendor personnel as part of their culture—yet they often hold just as much access.
Download: Traditional Security Awareness vs Human Risk Management
Traditional Security Awareness doesn’t do the job anymore. Download our guide to see how HRM upgrades your program and takes Security Awareness into your larger cybersecurity goals.

A Confident and Transparent Response
In the immediate aftermath, Coinbase did something many companies hesitate to do: it went public—fast, clear, and unapologetically firm.
CEO Brian Armstrong responded directly to the incident in a video posted to X (formerly Twitter), stating unequivocally that Coinbase would not pay the attackers’ $20 million ransom demand. Instead, the company offered a matching $20 million bounty for information leading to the arrest and conviction of those responsible.
“We’re not going to negotiate with criminals. That only encourages more of these attacks,” Armstrong said. “We’re going to work with law enforcement and the broader industry to bring these people to justice.”
This response wasn’t just PR—it was policy. Coinbase’s decision to go on the offensive, rather than retreat behind closed doors, signals a strategic, values-aligned stance on cybercrime. They communicated transparently, backed their principles with action, and reinforced the message that security posture isn’t just about tools—it’s about leadership.
In my experience, this level of visibility is rare—and commendable. It shows that Coinbase sees security not as a compliance requirement, but as part of its identity. That matters, especially when trust is on the line.

The Business Cost of Insider Risk
Coinbase may lose up to $400 million, depending on remediation costs, reimbursements, and potential litigation. But beyond financial loss, the true impact touches deeper areas of trust and operations:
Regulatory scrutiny, especially in the spotlight of its S&P 500 listing
Customer confidence, particularly among high-value traders and crypto-native users
Internal morale, as teams reflect on how human-layer risks are being managed
That said, Coinbase’s swift, transparent response—led directly by CEO Brian Armstrong—has likely helped limit long-term reputational damage. In my view, when companies own the narrative and lead decisively, they not only protect their credibility—they reinforce a security culture grounded in accountability.
We often think about security as stopping the “bad guys.” But sometimes, it’s about understanding the actions of well-meaning people—with just enough access, and just enough pressure—to make a critical mistake.
Why Insider Threats Are So Hard to Catch
Insider threats don’t always come with red flags. You’re not looking for a hacker in a hoodie—you’re trying to spot subtle decisions made under pressure, distraction, or deception.
According to IBM’s 2024 report:
60% of breaches involve insiders, either through error or intent
The average detection time is more than 200 days
That lines up with what I’ve seen across enterprise clients. When the vector is a human decision, the timeline to detection is often measured in months—not minutes.
How Human Risk Management Supports Insider Threat Prevention
This is where Human Risk Management (HRM) plays a vital role. Not by replacing your security stack—but by reinforcing it at the human layer, where access and behavior collide.
Here’s how we see HRM help organizations like Coinbase mitigate insider risk:
Make People Aware of the Social Engineering Risk
Coinbase’s breach wasn’t a software exploit. It was a human exploit. HRM delivers targeted education to high-risk roles like support agents—not in abstract, but in context, at the moment behavior happens.
Connect Behavior to Awareness, Not Just Access
Security tools may log what happened. HRM changes what happens next. When a user interacts with risky links or shares sensitive data, HRM delivers immediate, personalized feedback—building learning into the workflow.
Build a Behavior-Led Feedback Loop
We track performance on simulations, training engagement, and risky actions to build a behavioral baseline. That insight helps security teams spot not just anomalies—but habitual risk patterns.
Complement SOC Visibility with Human Context
If a SOC analyst sees unusual activity from a contractor, HRM provides behavioral context: has this user failed phishing tests before? Have they ignored previous nudges? Are they overdue for a training intervention?
Not a Replacement—A Reinforcement Layer
In my experience, companies sometimes ask, “Why didn’t our SIEM catch this?” The answer is: because people don’t trigger alerts the same way systems do. They rationalize. They click. They assume. And that’s where HRM comes in.
It doesn’t block access—it shapes behavior.
It doesn’t replace detection—it makes people more resilient to manipulation.
And it doesn’t teach once—it teaches in context, when risk is real.
How to defend against phishing attacks?
Visit our page to find out what are end-to-end phishing defense and what are its components.

Final Thought
The Coinbase breach didn’t come from a technical flaw. It came from human trust—granted to people without the tools, knowledge, or reinforcement to handle it.
In today’s enterprise environment, managing access isn’t enough. You need to manage behavior. That’s what Human Risk Management does best.
[Learn how HRM can help your team recognize and respond to insider risks →]



