Coinbase Cartel is a cyber-extortion group active since at least September 2025 that operates primarily as a data-theft-only extortion actor rather than a conventional encryption-focused ransomware crew. The group has publicly rejected the ransomware label in some reporting and is characterized by stealing data, maintaining victim system availability, and coercing payment through threats of publication on leak infrastructure. Its leak operations have used staged disclosure states and public victim naming, and the group has been tracked among active extortion brands during 2026 despite a sharp decline in public victim-post volume in Q2 2026. The actor has been associated with attacks against technology companies and source-code repositories, including incidents in which compromised credentials or tokens enabled access to developer environments and codebases. In one publicly reported case, the group claimed responsibility for a compromise of a software company’s GitHub environment and threatened to leak stolen source code unless paid. Reporting also describes a history of publishing stolen code on leak sites. More broadly, Coinbase Cartel has been linked by researchers to the English-speaking cybercriminal ecosystem surrounding ShinyHunters, Scattered Spider, and Lapsus$, placing it in a milieu known for social engineering, stolen credentials, cloud and SaaS abuse, and compromise of developer environments. Some reporting also places the group alongside the Silent Ransom Group lineage as an emerging data-extortion operation. Known aliases include STORM-2981 and the name Coinbase Cartel itself. The group has claimed victims in multiple regions, including South Korea, Slovenia, and the United States, and has been described as targeting technology companies in particular. Public reporting supports extortion and data exfiltration as core behaviors, while broader ecosystem links suggest overlap with credential-centric and social-engineering-heavy intrusion tradecraft; however, only exfiltration and extortion are directly established at high confidence for the actor itself from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An extortion group previously claiming two attacks against Ceva Logistics; mentioned as historical background, not as the identified actor behind the current incident.
Mentioned in quarterly rankings only.
Ransomware group that suffered the steepest decline in Q2 2026, possibly reflecting operational disruption.
Described as a prolific leak operation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.