The ransomware ecosystem is constantly evolving, with new groups abandoning traditional encryption methods and adopting more stealthy but equally dangerous strategies. One of the most notable cases is the Coinbase Cartel, a ransomware group that emerged in September 2025 and quickly captured the attention of cybersecurity analysts.
The group started aggressively, recording 14 victims within its first month of operation, showing early on that it had an organized infrastructure and a clear operational plan.
From ransomware to outright data theft
Unlike traditional ransomware groups that lock down systems through encryption, the Coinbase Cartel takes a different approach: it focuses solely on data theft.
See also: North Koreans pose as IT professionals on LinkedIn to infiltrate companies
This means that its attacks are often faster and harder to detect, as they do not cause immediately visible downtime. However, the threat remains just as serious, since the business model is based on extortion through leaks.
The message to victims is clear: pay to keep your data from being published online.
Which organizations are being targeted?
The Coinbase Cartel appears to be targeting organizations across multiple sectors, with financials ranging from millions to hundreds of billions of dollars in revenue.
According to Bitdefender, the group ranked among the 10 most active ransomware groups in both September and December 2025, with more than 60 victims in its first months of operation.
The sectors most affected are:
- Healthcare
- Technology
- Transportation
In fact, attacks on healthcare organizations represent over half of the targets.

Why the United Arab Emirates is in the spotlight
Of particular interest is the group's intense activity in healthcare facilities in the United Arab Emirates. In just one month, 10 healthcare organizations, raising questions about the group's true motives.
See also: From Ransomware to Permanent Access: The Rise of Digital Parasites
While economic benefit is a key factor, targeting a specific country may also imply geopolitical implications, with the potential aim of disrupting critical sectors of the UAE economy.
Coinbase Cartel: Infection Mechanisms and Operational Tactics
The Coinbase Cartel uses a wide range of techniques to gain initial access to victims' networks. Social engineering remains a key tool, while Initial Access Brokers , who sell ready-made compromised credentials on underground markets, also appear to play a significant role
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Once attackers gain access, they leverage administrator accounts to:
- modify security settings
- bypass recording mechanisms
- reduce the chances of detection
The data is then systematically removed before the victims' details are published on the group's leak website.
Blackmail with time limits and data auctions
The group implements strict blackmail schedules. Victims have:
- 48 hours to respond via dedicated chat interface
- 10 days to pay in Bitcoin or negotiate
At the same time, the existence of an auction page indicates that the Coinbase Cartel intends to generate revenue not only from ransom but also from selling the data through multiple channels.
An independent team with big ambitions
Unlike other modern gangs, the Coinbase Cartel does not operate on a Ransomware-as-a-Service model. Instead, it directly recruits cybercriminals and invests in advanced tools.
See also: Warlock Ransomware breached SmarterTools
In the fall of 2025, the group reportedly requested zero-day exploits with a budget of over $2 million, evidence of significant financial resources.

How can organizations protect themselves?
Experts recommend immediate defense measures, such as:
- Mandatory MFA on all accounts, especially administrators
- Systematic patch management to prevent initial access
- Recording and classifying critical data for enhanced protection
- Using Threat Intelligence to understand new tactics
- Managed Detection & Response services for rapid response to incidents
Although the group does not encrypt files, the threat of public data exposure makes the Coinbase Cartel one of the most worrying players in the new era of ransomware.
