Written by: Ben Weiss, Jeff John Roberts
Compiled by: Luffy, Foresight News

Coinbase co-founder and CEO Brian Armstrong spoke at an event in Bangalore, India, in 2022.
On May 15, 2025, Coinbase disclosed that the personal data of tens of thousands of its customers had been stolen, marking the largest security incident in the company's history, with losses expected to reach up to $400 million. The data breach is notable not only for its scale but also for the hackers' method of attack: bribing overseas customer service personnel to obtain confidential customer information.
Coinbase has publicly stated that it will pay a $20 million reward to whistleblowers who provide information leading to the arrest and conviction of criminals, but it has disclosed very little about the identity of the attackers or the details of the hacking incident.
(Fortune) magazine's recent investigation (including reviewing emails between Coinbase and a hacker) revealed new details about the incident, suggesting that a loose network of young English-speaking hackers is partially responsible. Meanwhile, the findings highlight that so-called BPOs (business process outsourcing units) are a weak link in tech companies' security operations.
Insider job: Outsourced customer service becomes the breach point
The story begins with a small public company, TaskUs, in New Braunfels, Texas. Like other BPOs, the company provides customer service for large tech firms at low cost by hiring overseas employees. According to a company spokesperson, in January of this year, TaskUs laid off 226 employees working for Coinbase from its service center in Indore, India.
According to documents submitted to the U.S. Securities and Exchange Commission, TaskUs has provided customer service personnel for Coinbase since 2017, a partnership that has saved the American crypto giant significant labor costs. But the problem is: when customers email to inquire about their accounts or Coinbase's new products, they are likely talking to TaskUs employees overseas. Because these agents are paid less than domestic U.S. employees, they are more susceptible to bribery.
"Earlier this year, we discovered that two individuals had illegally accessed information about one of our clients," a TaskUs spokesperson told (Fortune) magazine when referring to Coinbase. "We believe these two individuals were hired as part of a broader, organized criminal activity targeting Coinbase that also affected many other vendors providing services to Coinbase."
According to Coinbase's regulatory filings, TaskUs laid off employees in January, less than a month after Coinbase discovered customer data had been stolen (note: Coinbase discovered the data breach in December 2024). On Tuesday, a federal class-action lawsuit was filed in New York on behalf of Coinbase customers, accusing TaskUs of negligence in protecting customer data. "While we cannot comment on the lawsuit, we believe the allegations are unfounded, and we will defend ourselves," a TaskUs spokesperson said. "We prioritize the protection of customer data and will continue to enhance our global security protocols and training programs."
A source familiar with the security incident stated that the hackers also successfully attacked several other BPO companies, and the nature of the stolen data varied in each incident.
The stolen data was not enough for hackers to breach Coinbase's crypto vault, but it did provide ample information to help criminals impersonate fake Coinbase customer service, contacting customers and convincing them to give up their crypto assets. The company stated that hackers stole data from over 69,000 customers but did not specify how many became victims of the so-called "social engineering scam." In this case, the social engineering scam involved criminals using the stolen data to impersonate Coinbase employees, persuading victims to transfer their crypto assets.
Coinbase stated in a press release: "As we have disclosed, we recently discovered that a threat actor had requested overseas customer service to obtain customer account information dating back to December 2024. We have notified affected users and regulators, severed ties with the involved TaskUs personnel and other overseas customer service, and strengthened control measures." The statement also added that compensation is being offered to customers who lost money in the scam.
Social engineering scams impersonating company representatives are not new, but the scale of attacks targeting BPO companies is quite rare. While no one has explicitly identified the criminals yet, several clues strongly point to a loose organization of young English-speaking hackers.
Teen hacker gang: "They come from video games"
In the days following the disclosure of the Coinbase data breach in mid-May, (Fortune) magazine communicated on Telegram with a man who claimed to be one of the hackers, going by the name "puffy party."
Two other security researchers who spoke with the anonymous hacker told (Fortune) magazine that they found this person credible. One said, "Based on what he shared with me, I seriously scrutinized his statements and couldn't find evidence that his claims were false." Both researchers requested anonymity for fear of being subpoenaed for speaking with the so-called hacker.
In the communication, the man shared many screenshots, claiming these are email exchanges with the Coinbase security team. The name he used when communicating with Coinbase was "Lennard Schroeder." He also shared a screenshot of an account belonging to a former Coinbase executive, which displayed cryptocurrency transactions and a wealth of personal details.
Coinbase has not denied the authenticity of these screenshots.
The self-identified hacker shared emails that included threats to extort $20 million in Bitcoin (Coinbase refused to pay) and mocking comments about the hacker gang using part of the loot to buy hair for the company's bald CEO, Brian Armstrong. "We are willing to sponsor a hair transplant so he can travel the world in style," the hacker wrote.
In a Telegram message, this person (whose existence was revealed to (Fortune) magazine by a security researcher) expressed disdain for Coinbase.
Many cryptocurrency heists are carried out by Russian crime gangs or the North Korean military, but this hacker is reportedly part of a loose alliance of teenagers and young adults known as "Comm" or "Com."
Over the past two years, reports about the Comm gang have appeared in media coverage of other hacking incidents, including a New York Times article earlier this month, where one suspect in a series of cryptocurrency thefts claimed to be a member of the group. According to the Wall Street Journal, in 2023, investigators linked the group to hackers who attacked several online casinos in Las Vegas and attempted to extort $30 million from MGM Resorts.
Unlike the typical Russian and North Korean crypto hackers who usually pursue money, members of the Comm gang tend to seek attention and the thrill of mischief. They sometimes collaborate on hacking attacks, but they also compete with each other to see who can steal more.
"They come from video games, and then they bring high scores to the real world," said Josh Cooper-Duckett, director of investigations at the forensic investigation firm Cryptoforensic Investigators. "In this world, their score is how much money they've stolen."
In a Telegram message, the so-called hacker stated that members of Comm are responsible for different aspects of the robbery. His team bribes customer service and collects customer data, then hands the data over to others in the team who are proficient in social engineering scams. They added that different Comm affiliates coordinate how to execute different parts of the operation on social platforms like Telegram and Discord and distribute the loot.
Sergio Garcia, founder of the crypto investigation company Tracelon, told (Fortune) magazine that the hacker's description of the attack on Coinbase aligns with his observations of how the Comm gang operates and other crypto social engineering scams. Insiders noted that the individuals attacking customers in recent social engineering scams spoke fluent North American English.
According to a source familiar with BPO employee salaries, the monthly salary of TaskUs employees in India ranges from $500 to $700. TaskUs declined to comment. Garcia told (Fortune) magazine that while this figure is higher than India's per capita GDP, the low wages for customer service often make them more susceptible to bribery. "Clearly, this is the weakest link in the chain as they have the financial incentive to accept bribes," he added.
