
Coinbase breach linked to customer data leak in India, sources say
At least one part of the breach, publicly disclosed in a May 14 SEC filing, occurred when an India-based employee of the U.S. outsourcing firm TaskUs was caught taking photographs of her work computer with her personal phone, according to five former TaskUs employees.
Three of the employees and a person familiar with the matter said Coinbase was notified immediately.
The ex-employees said they were briefed on the matter by company investigators or colleagues who witnessed the incident in the Indian city of Indore, noting that the woman and a suspected accomplice were alleged to have been feeding Coinbase customer information to hackers in return for bribes.
The ex-employees and person familiar with the matter said more than 200 TaskUs employees were soon fired in a mass layoff that drew Indian media attention.
Coinbase had previously blamed "support agents overseas" for the breach, which it estimated could cost up to $400 million.
Although the link between TaskUs and the breach was previously alleged in a lawsuit filed last week in federal court in Manhattan, details of the incident, reported here for the first time, raise further questions over when Coinbase first learned of the incident.
Coinbase said in the May SEC filing that it knew contractors accessed employee data "without business need" in "previous months." Only when it received an extortion demand on May 11 did it realize that the access was part of a wider campaign, the company said.
In a statement to Reuters on Wednesday, Coinbase said the incident was recently discovered and that it had "cut ties with the TaskUs personnel involved and other overseas agents, and tightened controls."
Coinbase did not disclose who the other foreign agents were.
TaskUs said in a statement that two employees had been fired early this year after they illegally accessed information from a client, which it did not identify.
"We immediately reported this activity to the client," the statement said. "We believe these two individuals were recruited by a much broader, coordinated criminal campaign against this client that also impacted a number of other providers servicing this client."
The person familiar with the matter confirmed that Coinbase was the client and that the incident took place in January.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CNA
15 hours ago
- CNA
Indian tech company TCS to cut workforce by 2%, affecting more than 12,000 jobs
BENGALURU :India's largest IT services provider Tata Consultancy Services will reduce its workforce by 2 per cent in its 2026 financial year, primarily affecting middle and senior management, the company said on Sunday. The company is retraining and redeploying staff as it enters new markets, invests in new technology and deploys AI, but about 12,200 jobs will be cut as part of the process, it said. "This transition is being planned with due care to ensure there is no impact on service delivery to our clients," the company added. India's $283 billion IT sector has had to contend with clients holding back non-essential technology spending because of weak demand, persistent inflation and lingering uncertainty over U.S. trade policies.


CNA
18 hours ago
- CNA
Six crushed to death in India temple stampede
HARIDWAR, India: At least six people were crushed to death at a popular Hindu temple in northern India's Uttarakhand state on Sunday (Jul 27), officials said, after a massive crowd surge. The stampede occurred on the stairway leading to the Mansa Devi temple in the Hindu holy city of Haridwar, on the banks of the Ganges river, and left many injured. "Six dead and more than 10 injured are admitted to the hospital," senior city police official Parmendra Dobhal told AFP. Uttarkhand Chief Minister Pushkar Singh Dhami said relief and rescue operations were underway. "I am constantly in touch with the local administration regarding this matter and continuous monitoring of the situation is being done," he said in a statement. Deadly stampedes and crowd crushes are a common occurrence at Indian religious festivals. In June, a sudden crowd surge at a Hindu festival in the coastal state of Odisha triggered a stampede that killed at least three people and injured several others. The previous month six people were crushed to death in the western state of Goa after thousands gathered for a popular fire-walking ritual. And in January, at least 30 people were killed in an early morning crush at the Kumbh Mela, a Hindu mega-festival in the northern city of Prayagraj.


CNA
2 days ago
- CNA
Xavi application for India coaching job was a hoax, AIFF says
The All India Football Federation (AIFF) confirmed on Saturday that a job application attributed to former Barcelona manager and Spain midfielder Xavi Hernandez for the India head coaching role was a hoax. The AIFF's national team director told The Times of India on Thursday that Xavi's name was on the list of applicants. The report also quoted an AIFF technical committee member saying the his candidacy was deemed too expensive to pursue. "The AIFF received an email furnishing the applications from Spanish coaches Pep Guardiola and Xavi Hernandez. The authenticity of their applications could not be confirmed, and it has since emerged that the email applications were not genuine," the AIFF said in a statement. It had not been previously reported that the AIFF had also received an application purporting to be from Manchester City manager Guardiola. The AIFF Technical Committee said it had reviewed 170 applications for the Indian men's head coach role, narrowing the list to 10 before short-listing three candidates. The AIFF sacked former India manger Igor Stimac in June last year before appointing Spaniard Manolo Marquez, who left the job this month and returned to his role as coach of Indian Super League team FC Goa.