Mastodon Skip to content
pulseofnations. Real News. Global Impact.
live markets
S&P 5007,652.86▲ 3.25%NASDAQ25,980.19▲ 4.02%DOW53,417.16▲ 2.83%GOLD4,709.80▲ 15.79%WTI85.01▼ 4.81%BRENT92.00▼ 4.94%EUR/USD1.1666▲ 2.54%USD/JPY159.14▼ 2.86%DXY99.00▼ 2.43%BTC$78,641▲ 1.60%ETH$2,467▲ 0.77%SOL$95.88▲ 0.59%TOTAL CRYPTO$2.66T▼ 0.73%

CoinbaseCartel Blitz Hits 13+ Firms Across 7 Countries

Data-theft extortion group claims victims from German e-commerce to Indonesian banks in 24-hour spree targeting healthcare, finance and manufacturing

Partner Surfshark VPN

The CoinbaseCartel ransomware group has claimed more than a dozen victims in a single 24-hour period, targeting companies across seven countries in what security researchers describe as one of the group’s most aggressive campaigns since it emerged in late 2025. The blitz, disclosed on August 24, spans healthcare, financial services, transportation, manufacturing, and professional services sectors.

Among the most prominent targets is Westwing Group SE, a publicly traded German e-commerce company valued at over 1 billion euros. The group also listed Tower Insurance Limited, one of New Zealand’s oldest insurance providers, and RXPE Group, a Chinese energy company, according to breach disclosures from August 24.

The full list of claimed victims spans at least 13 organizations across the United States, Germany, New Zealand, Indonesia, France, Argentina, and the United Kingdom. Other targets include Integrated Health Systems, Abacus Advisors, Klasko Immigration Law Partners, and PT BPR Bintan, an Indonesian bank.

How CoinbaseCartel Operates

CoinbaseCartel operates as a data-theft-only extortion group, stealing corporate data and threatening to publish it on its Tor-based leak site unless payment is made. Unlike traditional ransomware, the group does not encrypt victim files or disrupt systems. Instead, it uses credentials stolen from infostealer malware infections, including RedLine, Lumma, and Vidar, to access corporate cloud platforms and exfiltrate data.

The group has ties to the broader Scattered Lapsus$ Hunters affiliate ecosystem, with both ShinyHunters and Scattered Spider identified as affiliates. Since its debut in September 2025, CoinbaseCartel has accumulated over 200 claimed victims across 36 countries, making it one of the most prolific extortion operations in the current threat landscape.

Velocity Surge Raises Alarm

Security analysts note that the group’s attack velocity has surged, with ransomware.live data showing a 380 percent increase in CoinbaseCartel activity over the past month. The August 24 spree represents a return to peak form after a 54 percent decline in the group’s second-quarter 2026 output. The spike suggests renewed affiliate recruitment or a fresh batch of stolen credentials being deployed.

Once contact is established, a 10-day window opens for payment or negotiation. The group accepts ransom payment exclusively in Bitcoin.

The breadth of targets across sectors and geographies underscores a shift in ransomware tactics away from single high-value targets toward volume-based extortion. Security experts recommend that organizations audit their cloud access credentials, deploy infostealer detection tools, and review data loss prevention policies to counter the credential-harvesting approach that powers CoinbaseCartel’s operations.

SourcesHalcyon; ransomware.live; DeXpose; BleepingComputer; breachsense.com
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Emperador Ransomware Hits Vietnam Power Giant, Exposes 300GB Read →