Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Coinbase Cartel is an encryption-free (single-extortion) data-theft-and-extortion group that surfaced on dark-web leak sites in September 2025 and rapidly reached the top-10 most active extortion brands globally within its first months. It does not deploy file-encrypting ransomware; instead it obtains valid credentials (heavily reliant on infostealer logs), accesses networks, exfiltrates data, and threatens publication on its data-leak site unless paid. Victims are given a 48-hour response window and roughly a 10-day window to pay in Bitcoin or negotiate before data is published.
The group posted its first victim listings in September 2025 and grew quickly across healthcare, technology, transportation and logistics sectors. Hudson Rock, cross-referencing ransomware.live tracking, counted roughly 160-164 claimed victims by April 2026, and found approximately 80% of victim organizations had prior infostealer infections indexed in Hudson Rock's Cavalier database — some with employee credentials exposed years before the attacks, underscoring an infostealer-credential-driven access model. In early 2026 the leak site added an 'auctions' section allowing third parties to buy stolen datasets. Vendors including Bitdefender, SOCRadar, Fortinet/FortiGuard, Halcyon, WatchGuard, Hive Pro and Proven Data have published profiles, so this is a well-corroborated, genuinely active 2025-2026 extortion brand rather than a fabricated or single-source leak-site listing. New listings slowed after April 2026, and reporting characterizes the operation as trending toward dormancy; status is marked dormant given activity had tapered by the time of writing (Sept 2026), though it could resurface. MENA relevance: REAL and directly reported, not thin. In December 2025 Coinbase Cartel claimed breaches of roughly 10 major UAE real estate firms (including Betterhomes / bhomes.com on 9 Dec 2025) and researchers separately observed an unusual single-month cluster of ~10 UAE healthcare organizations on the leak site — an atypical concentration that prompted analysts to question whether more than financial motives were at play. The UAE country tag on the RaqibCTI record is therefore justified by concrete, multi-source leak-site victimology.