logo

Inside the Coinbase Cartel: How Infostealer Credentials Fueled a 100+ Company Ransomware Spree

ID: 510843a5-57e7-5b01-9f62-ca0b90e7ed77

STIX ID: report--510843a5-57e7-5b01-9f62-ca0b90e7ed77

Feed Name: infostealers.com

Threat Score
78/100

Date Published: 2026-04-27

Date Updated: 2026-04-28

Author: InfoStealers

...
...

Hudson Rock's report profiles Coinbase Cartel, an extortion-only ransomware group active since 2025 that leverages years-old Infostealer-derived credentials to quietly access cloud/FTP/file-sharing infrastructure, exfiltrate corporate data, and publish leaks across 100+ high-value victims (healthcare, tech, transportation, etc.); the report includes correlation analysis with Hudson Rock’s Cavalier database, five detailed case studies (Aptim, Canada Goose, Efficy, The Epoch Times, RAKS), and a warning about the long-lived risk posed by compromised credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.