The CoinbaseCartel ransomware group has claimed more than a dozen victims in a single 24-hour period, targeting companies across seven countries in what security researchers describe as one of the group’s most aggressive campaigns since it emerged in late 2025. The blitz, disclosed on August 24, spans healthcare, financial services, transportation, manufacturing, and professional services sectors.
Among the most prominent targets is Westwing Group SE, a publicly traded German e-commerce company valued at over 1 billion euros. The group also listed Tower Insurance Limited, one of New Zealand’s oldest insurance providers, and RXPE Group, a Chinese energy company, according to breach disclosures from August 24.
The full list of claimed victims spans at least 13 organizations across the United States, Germany, New Zealand, Indonesia, France, Argentina, and the United Kingdom. Other targets include Integrated Health Systems, Abacus Advisors, Klasko Immigration Law Partners, and PT BPR Bintan, an Indonesian bank.
How CoinbaseCartel Operates
CoinbaseCartel operates as a data-theft-only extortion group, stealing corporate data and threatening to publish it on its Tor-based leak site unless payment is made. Unlike traditional ransomware, the group does not encrypt victim files or disrupt systems. Instead, it uses credentials stolen from infostealer malware infections, including RedLine, Lumma, and Vidar, to access corporate cloud platforms and exfiltrate data.
The group has ties to the broader Scattered Lapsus$ Hunters affiliate ecosystem, with both ShinyHunters and Scattered Spider identified as affiliates. Since its debut in September 2025, CoinbaseCartel has accumulated over 200 claimed victims across 36 countries, making it one of the most prolific extortion operations in the current threat landscape.
Velocity Surge Raises Alarm
Security analysts note that the group’s attack velocity has surged, with ransomware.live data showing a 380 percent increase in CoinbaseCartel activity over the past month. The August 24 spree represents a return to peak form after a 54 percent decline in the group’s second-quarter 2026 output. The spike suggests renewed affiliate recruitment or a fresh batch of stolen credentials being deployed.
Once contact is established, a 10-day window opens for payment or negotiation. The group accepts ransom payment exclusively in Bitcoin.
The breadth of targets across sectors and geographies underscores a shift in ransomware tactics away from single high-value targets toward volume-based extortion. Security experts recommend that organizations audit their cloud access credentials, deploy infostealer detection tools, and review data loss prevention policies to counter the credential-harvesting approach that powers CoinbaseCartel’s operations.
discussion