
CoinbaseCartel
Data as of September 14, 2026.
Credential exposure before the attack
38.8% of CoinbaseCartel victims whose domain we can identify (66 of 170) had employee credentials leak in the 12 months before CoinbaseCartel named them as a victim.
We don't know whether any of these credentials were how CoinbaseCartel gained initial access.
What industries CoinbaseCartel targets
Sector identified for 130 of 170 victims.
| Technology | 26 | |
| Financial Services | 21 | |
| Manufacturing | 19 | |
| Healthcare | 11 | |
| Logistics | 10 | |
| Construction | 8 | |
| Retail | 5 | |
| Telecommunications | 5 |
Where the victims are located
Country identified for 158 of 170 victims.
| United States | 65 | |
| France | 10 | |
| Canada | 9 | |
| United Kingdom | 9 | |
| United Arab Emirates | 9 | |
| Indonesia | 6 | |
| Germany | 5 | |
| Switzerland | 4 |
Most recent CoinbaseCartel victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| Abacus Advisors abacusadv.com | Financial Services | United States | Aug 24, 2026 |
| PT Jamu Air Mancur airmancur.biz | Not identified | Indonesia | Aug 24, 2026 |
| PT BPR Bintan bprbintan.co.id | Financial Services | Indonesia | Aug 24, 2026 |
| Flecha Bus flechabus.com.ar | Logistics | Argentina | Aug 24, 2026 |
| Integrated Health Systems ihs911.com | Healthcare | United States | Aug 24, 2026 |
| Kessler Creative kesslercreative.com | Not identified | United States | Aug 24, 2026 |
| Klasko Immigration Law Partners klaskolaw.com | Legal | United States | Aug 24, 2026 |
| LifeBank Microfinance Foundation lifebankfoundation.org | Non-profit | Philippines | Aug 24, 2026 |
| Longhorn Investments longhorninvestments.com | Real Estate | Not identified | Aug 24, 2026 |
| OTEIS Conseil & Ingénierie oteis.fr | Construction | France | Aug 24, 2026 |
| Patel & Company patelcpaoffice.com | Financial Services | United States | Aug 24, 2026 |
| RXHK rxhk.co.uk | Energy | United Kingdom | Aug 24, 2026 |
| Tower Insurance Limited tower.co.nz | Financial Services | New Zealand | Aug 24, 2026 |
| Advanced Engineering Consultants aecmep.com | Not identified | United States | Aug 20, 2026 |
| Crowe crowe.com | Not identified | Not identified | Aug 20, 2026 |
| Serruya Private Equity serruyaprivateequity.com | Financial Services | Canada | Aug 17, 2026 |
| Sweetwater swhco.com | Financial Services | United States | Aug 17, 2026 |
| Turner & Townsend turnerandtownsend.com | Real Estate | United Kingdom | Aug 17, 2026 |
| Hitachi High-Tech hitachi-hightech.com | Manufacturing | Japan | Aug 14, 2026 |
| CEN and CENELEC cencenelec.eu | Non-profit | Belgium | Aug 3, 2026 |
Showing the 20 most recent of 170. Browse recent data breaches for more.
CoinbaseCartel leak sites
Addresses we've seen CoinbaseCartel publish victims from. Any .onion address needs the Tor Browser.
fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onionincblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion
CoinbaseCartel questions
Is CoinbaseCartel still active?
Yes. CoinbaseCartel posted its most recent victim on August 24, 2026. That's 19 victims in the last 30 days.
How many victims has CoinbaseCartel claimed?
CoinbaseCartel has named 170 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did CoinbaseCartel first appear?
The first victim we recorded for CoinbaseCartel was posted on September 16, 2025. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does CoinbaseCartel target?
Technology accounts for the most victims we can classify, with 26. Financial Services follows at 21. We could identify a sector for 130 of 170 victims, so treat this as the shape of the targeting rather than a full census.
Has CoinbaseCartel already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.