Criterica Intelligence — production models trained on real court records, not synthetic data
Data Breach — MDL No. 3153

Coinbase

U.S. District Court for the Southern District of New York

The Coinbase Customer Data Security Breach litigation was centralized before Judge Edgardo Ramos in the Southern District of New York in August 2025, consolidating claims arising from a 2025 incident reportedly involving compromised customer-support contractors who accessed Coinbase customer account and personal information, which was subsequently used in targeted social-engineering and account-takeover attempts against affected customers. With 17 pending actions, this is an early-stage docket within the data-breach category.

What distinguishes this docket structurally is the insider-access vector: rather than an external attacker exploiting a software vulnerability, the reported exposure involved compromised third-party contractors with legitimate customer-support access, raising liability questions specific to vendor oversight, access controls, and employee or contractor vetting practices rather than the network-security questions typical of an external-hacking breach. That distinction may shape both the discovery focus and the applicable negligence standard as the litigation develops.

The cryptocurrency-exchange context also introduces a distinctive harm dimension: because exposed account information was reportedly used in follow-on account-takeover attempts targeting digital-asset holdings, damages theories in this docket may extend to actual or attempted financial loss in a way that is more concrete than the identity-theft-risk theories common to many data-breach dockets, potentially affecting how courts assess standing and damages. Criterica Intelligence's platform tracks this insider-access and financial-services-sector breach pattern distinctly from external-hacking dockets, given the different liability theories and harm profiles involved. A companion capital brief on this docket is available through Criterica Capital.

Frequently Asked Questions
What is distinctive about how this breach reportedly occurred?

Exposure reportedly resulted from compromised customer-support contractors with legitimate account access, an insider-access vector rather than an external attacker exploiting a software vulnerability.

How does that affect the liability theory in this docket?

It shifts focus toward Coinbase's vendor-management, access-control, and contractor-vetting practices, rather than the network-security questions typical of an external-hacking breach.

Why might this docket involve different harm than a typical data breach?

Because exposed account information was reportedly used in targeted account-takeover attempts against digital-asset holdings, potential harm may include actual or attempted financial loss rather than only identity-theft risk.

What stage is this litigation in?

An early stage — centralized in August 2025 with 17 pending actions, so no bellwether process or settlement framework has yet developed in this proceeding.

Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.

← All Pending MDLsFunding brief on Criterica Capital →