Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Coinbase employees were targeted on February 5, 2023, in an SMS-phishing attack that Coinbase linked to the 0ktapus threat group. One employee entered login credentials on a fake site; when two-factor authentication blocked the attacker from using them immediately, the attacker called while impersonating Coinbase IT and tried to persuade the employee to log in to a workstation. Coinbase’s security team detected suspicious activity and intervened. The company said limited employee contact details were obtained, but customer information was not compromised and no funds were stolen in this incident.
What happened in the Coinbase attack
The incident began with a text message directing an employee to a fraudulent login page. The employee entered a username and password, giving the attacker valid credentials. But those credentials alone were not enough to get in: Coinbase’s two-factor authentication (2FA) blocked immediate access.
About 20 minutes later, the attacker called the employee and claimed to be from Coinbase’s IT department. The caller tried to persuade the employee to log in to a workstation, turning a credential-phishing attempt into a live social-engineering effort. Coinbase’s security team detected suspicious activity, contacted the employee and stopped the intrusion from progressing further.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsThe attacker obtained limited employee contact information, including names, email addresses and phone numbers. Coinbase said customer information was not compromised and no funds were stolen. This was an attack against Coinbase personnel and an attempted internal intrusion—not a reported theft from customers’ cryptocurrency accounts.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What was—and was not—compromised
| Reported in the incident | Not reported as compromised |
|---|---|
| Employee credentials entered on a fraudulent site | Customer account information |
| Limited employee names, email addresses and phone numbers | Customer funds or cryptocurrency |
| An attempt to persuade an employee to access a workstation | A confirmed compromise of Coinbase’s customer platform |
Coinbase said the attacker accessed a corporate directory. The reporting does not establish that the employee contact details were later used in another intrusion. Exposure of names and contact information can, however, make follow-up impersonation or phishing more convincing.
Why 2FA did not end the attack
2FA did its job in one important respect: a stolen password was not sufficient for immediate access. The attacker then changed tactics, using a phone call and a false IT identity to try to get the employee to take an action on a workstation. This is why it is inaccurate to say simply that MFA failed—or to treat MFA as a complete defense against determined social engineering.
Controls work best in layers. Phishing-resistant authentication, such as hardware security keys, makes it harder to use credentials on a fake login page. Clear rules for verifying help-desk requests can reduce the chance that a caller can persuade an employee to bypass normal safeguards. Identity and endpoint monitoring can help detect unusual activity, while a rapid incident-response process can limit what happens after a mistake.
Cloudflare, one of the organizations targeted in the related 2022 campaign, said hardware security keys helped protect its systems. That is a useful example of phishing-resistant authentication, not a guarantee against every kind of account takeover or social engineering.
Rank #2
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Who is 0ktapus, and how does Scattered Spider fit?
Coinbase linked the 2023 attack to 0ktapus, a name used for a financially motivated campaign known for SMS phishing and attempts to capture employee credentials and two-factor authentication codes. Its targets included organizations whose staff used identity and access-management services. The Coinbase attribution should be understood as a likely link, not as public proof establishing the operators’ identities.
Reporting often connects 0ktapus with Scattered Spider, but threat-group names are not always used consistently. MITRE ATT&CK lists Scattered Spider as group G1015 and associates it with names including Roasted 0ktapus, Octo Tempest, STORM-0875 and UNC3944. These labels can describe overlapping activity, aliases or related clusters; they do not, by themselves, prove that every campaign was run by one fixed organization.
MITRE ATT&CK’s Scattered Spider profile documents the group designation and associated names. For this incident, the careful wording is that Coinbase linked the attack to 0ktapus and that 0ktapus is associated in reporting with the broader Scattered Spider activity—not that attribution is certain.
Connection to the 2022 Twilio and Cloudflare attacks
The Coinbase incident came months after SMS-phishing attacks against Twilio, Cloudflare and other organizations in 2022. The common pattern was to text employees links to fake sign-in pages and use stolen identity credentials to pursue access to corporate systems. The connection is the attack method and reported threat-cluster association; Coinbase was targeted in February 2023, not during the 2022 incidents.
Rank #3
- FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
- Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
- Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
- Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
- FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.
Group-IB’s investigation, as reported by The Hacker News, identified 136 organizations and 9,931 compromised accounts in the wider campaign. Those are researchers’ reported campaign figures, not independently audited totals. Cloudflare said at least 76 employees and family members were targeted with similar smishing messages and that hardware security keys helped prevent access to its systems.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Practical lessons for companies
- Make authentication phishing-resistant where possible. Hardware security keys or other phishing-resistant methods can reduce the value of credentials entered on a fake page.
- Verify IT requests through a separate, trusted channel. Employees should not rely on caller ID or a caller’s claimed role. Requests to sign in, approve access or change account settings should follow documented verification procedures.
- Train for channel-switching attacks. A suspicious text may be followed by a convincing call. Employees should know how to report both without continuing the interaction.
- Monitor identity and endpoint activity. Unusual sign-ins, workstation access or other activity can help security teams intervene before an attacker moves deeper into the environment.
- Limit directory exposure. Restricting access to employee contact information can reduce what an intruder can collect and use to make later pretexts more credible.
- Practice a fast response. Clear reporting routes and an incident-response team that can promptly contact an employee can help contain an attempted intrusion.
What Coinbase customers should know
The incident described here did not involve reported customer-account compromise or stolen customer funds, so it does not by itself establish that customers need to reset passwords or move cryptocurrency. Customers should still treat unsolicited messages and urgent calls claiming to be from Coinbase with caution: do not follow their links or disclose passwords or authentication codes. Open the official app or navigate to the official website independently, and contact support through official channels if you believe you were directly targeted.
SecurityWeek’s report on the Coinbase incident covers the timeline, Coinbase’s stated impact and its attribution. The Record’s report provides further detail on the corporate-directory access.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

