In May 2025, Coinbase disclosed that a group of its overseas customer support contractors had been bribed to exfiltrate customer data from internal systems. The attackers then contacted Coinbase demanding $20 million in exchange for not publishing the stolen records. Coinbase refused, disclosed the breach publicly, and set aside up to $400 million to cover remediation costs and customer compensation.
No systems were compromised. No credentials were stolen. No vulnerability was exploited. The people who took the data had legitimate access to it as part of their job. They used that access, as they were entitled to, and then used it again for purposes they were not entitled to. From the perspective of every technical control in place, nothing unusual happened until it was already too late.
This is the insider threat problem in its purest form, and it is one the security industry has never solved with perimeter or identity controls - because the insider is already past both. Behavioural analytics can flag anomalies after the fact. Data loss prevention tools can catch some exfiltration patterns. Monitoring can reduce dwell time. None of it changes the fundamental reality that a person with legitimate access, willing to abuse it, can reach the data they are authorised to reach and take it.
The question the Coinbase breach raises is not how to detect a malicious insider faster. It is why bulk access to sensitive customer records did not require a confirmed authority decision from someone outside the support function before it executed.
GoFirm addresses this directly. Bulk data exports - regardless of whether they are initiated by an external attacker, a compromised account, or a legitimately credentialled insider - are configured as high-consequence actions requiring a named authority confirmation before execution. The support contractor who has been bribed to exfiltrate records cannot produce a biometric confirmation from the CFO, the data protection officer, or whoever the organisation has designated as the authority for that action type.
There is a second layer worth noting. Even in the scenario where the named authority is the compromised party - where the insider is senior enough to be the designated approver - their biometric confirmation on their registered device is captured, signed, timestamped, and permanently recorded. The forensic trail is unambiguous. The accountability is on record.
Coinbase's breach was not a technology failure. Every system worked as designed. The gap was at the execution boundary of a consequential data access action, where no confirmed authority requirement existed. That is precisely where GoFirm operates.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligations, in seconds not days.
References
1. Coinbase Global Inc., Form 8-K Security Incident Disclosure, May 2025
2. American Banker, The Seven Largest Banking Data Breaches of 2025, December 2025
