SYMBOLCOMMON_NAMEaka. SYNONYMS

Coinbase Cartel  (Back to overview)


Coinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 victims, primarily in the healthcare, technology, and transportation sectors. The group employs TTPs such as social engineering, credential harvesting, and collaboration with Initial Access Brokers to gain initial access. They operate a data leak site where they publish victim names and issue ransom demands, requiring payment via Bitcoin.


Associated Families

There are currently no families associated with this actor.


References
2026-02-09BitdefenderJade Brown
No Encryptors, No Problem: The Coinbase Cartel Ransomware Group
Coinbase Cartel

Credits: MISP Project