| SYMBOL | COMMON_NAME | aka. SYNONYMS |
Coinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 victims, primarily in the healthcare, technology, and transportation sectors. The group employs TTPs such as social engineering, credential harvesting, and collaboration with Initial Access Brokers to gain initial access. They operate a data leak site where they publish victim names and issue ransom demands, requiring payment via Bitcoin.
There are currently no families associated with this actor.
| 2026-02-09
⋅
Bitdefender
⋅
No Encryptors, No Problem: The Coinbase Cartel Ransomware Group Coinbase Cartel |