Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Coinbase employees were targeted in an SMS-phishing attack on February 5, 2023. One employee entered credentials on a fake login page; about 20 minutes later, the attacker called while posing as Coinbase IT and tried to persuade the employee to log in to a workstation. Coinbase’s security team detected suspicious activity and intervened. The company said limited employee contact details were obtained, but customer information was not compromised and no funds were stolen. Coinbase linked the attack to 0ktapus, the threat cluster associated with the 2022 Twilio and Cloudflare phishing campaign.

What happened in the Coinbase attack

The incident began with a text message urging a Coinbase employee to follow a link and log in. The link led to a fraudulent page that captured the employee’s username and password. Coinbase said two-factor authentication (2FA) prevented the attacker from immediately using those credentials to access the account.

About 20 minutes later, the attacker called the employee, claimed to be from Coinbase’s IT department and tried to persuade the employee to log in to a workstation. Coinbase’s security team detected suspicious activity, contacted the employee and stopped the attempted intrusion. The sequence—text message, fake login page, then an IT-impersonation call—made this more than a simple password-theft attempt. SecurityWeek’s February 20, 2023 report describes the incident and Coinbase’s account of its response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the attackers accessed—and what they did not

Coinbase said the attackers obtained limited employee contact information: names, email addresses and phone numbers. The available reporting does not establish that this information was later used in another attack.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Coinbase said customer information was not compromised and no funds were stolen in this incident. That distinction matters: this was an attack on employees and an attempted move into the corporate environment, not a reported breach of customer wallets or a theft of cryptocurrency. It is also too broad to say Coinbase systems were untouched; an employee’s credentials were captured, an attacker tried to gain workstation access, and some employee information was obtained.

Why the attacker called after stealing a password

Two-factor authentication made the stolen password insufficient on its own. The follow-up call was an attempt to get around that obstacle by manipulating the employee into taking an action that would enable access. The caller invoked IT’s authority, a familiar pretext in attacks that target employees and help desks.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

That does not mean 2FA failed. It blocked immediate use of the password, while the attacker tried a different route: persuading a person to help complete the login or open a workstation. The incident illustrates why authentication needs to be paired with procedures that make unexpected support requests difficult to exploit, as well as monitoring that can catch unusual identity or endpoint activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who are 0ktapus and Scattered Spider?

Coinbase linked the attack to 0ktapus, a name used for a financially motivated phishing campaign that targeted employees with SMS messages and fake sign-in pages. The campaign sought credentials and, in some cases, authentication codes to reach company identity systems and internal services.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Coverage of the 2023 Coinbase incident described 0ktapus as also known as Scattered Spider. Threat-group labels are not always consistent, however: a campaign name, an alias and a broader criminal group are not necessarily interchangeable or proof of one fixed organization. MITRE ATT&CK’s Scattered Spider profile lists associated names including Roasted 0ktapus, Octo Tempest, STORM-0875 and UNC3944. The careful conclusion is that Coinbase attributed the attack to 0ktapus, a cluster linked in reporting to activity associated with Scattered Spider—not that public evidence conclusively established the identity of the individual operators.

How the attack connects to Twilio and Cloudflare

The connection is the similar SMS-phishing approach used against Twilio, Cloudflare and other organizations in 2022. Those earlier attacks targeted employees with texts designed to lead them to fake login pages and steal work credentials. Coinbase was targeted later, in February 2023; it was not part of the 2022 incidents simply because the attacks were linked to the same campaign or threat cluster.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Group-IB research cited in reporting on the wider 2022 campaign identified 136 organizations and 9,931 compromised accounts. These are researchers’ reported figures, not an independently audited count. Cloudflare said at least 76 of its employees and family members were targeted with similar smishing messages. It credited its use of hardware security keys with helping prevent the attackers from accessing its systems. That is a useful example of phishing-resistant authentication, not a guarantee that any single control defeats every attack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What companies can learn

  • Make authentication phishing-resistant where practical. Hardware security keys and other phishing-resistant methods are harder to defeat with a fake login page than passwords or codes that can be entered into one. They are a stronger control, not a substitute for secure account recovery or response procedures.
  • Verify support requests through a trusted route. Employees should not rely on caller ID or an unsolicited caller’s claimed identity. A request to log in, approve a prompt or change account settings should be confirmed through an established internal channel.
  • Watch identity and endpoint activity together. A valid password can still be used in an unusual way. Monitoring for suspicious sign-ins and workstation activity can help teams identify an intrusion attempt before it spreads.
  • Limit employee-directory exposure. Names, email addresses and phone numbers can make later impersonation more convincing. Restrict access to directories where possible and treat exposed contact details as a potential source of follow-on risk.
  • Prepare for channel-switching attacks. Employees should know that an attacker may move from text to phone call after a credential is captured. Training should explain how to report both the original message and a follow-up call quickly.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Coinbase customers should take from it

The reported incident does not establish that customers needed to move cryptocurrency or reset passwords. Customers should still avoid links in unexpected texts or emails, open Coinbase through its official app or by navigating to its site independently, and never share a password or authentication code with someone claiming to be support. If a message or call appears to concern an account, contact Coinbase through its official support channels rather than using contact details supplied by the sender.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How certain is the attribution?

Coinbase linked the attack to 0ktapus, and reporting connected that cluster to the 2022 Twilio and Cloudflare campaign. Attribution based on campaign patterns and threat intelligence is not the same as public proof of the operators’ identities. For that reason, “linked to” or “attributed by Coinbase to” is more precise than saying Scattered Spider was definitively proven to have carried out the attack.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.