Cybersecurity firm Kaspersky has uncovered a phishing campaign aimed at users of Coinbase, one of the world’s most popular cryptocurrency exchanges, with attackers attempting to steal login credentials and gain full access to victims’ accounts.
The scheme began with emails urging Coinbase users to download and view their account statements. Recipients were told the documents could only be opened on Windows-based desktops or laptops. Once the file was downloaded and opened, it secretly installed remote access software, giving cybercriminals control of the victim’s device.
Victims were then prompted to log in to their Coinbase account, unknowingly exposing their credentials to the attackers. With these details, the attackers could siphon cryptocurrency funds or lock users out of their accounts altogether.
Screenshots obtained by Kaspersky showed the attackers’ dashboard, which allowed them to monitor compromised users and manage stolen credentials.
“This phishing campaign is a stark reminder of how cybercriminals exploit trusted platforms like Coinbase to deceive users,” said Olga Altukhova, Senior Web Content Analyst at Kaspersky. “By masquerading their tool as a legitimate account statement, attackers are weaponizing user trust. Legitimate services would never ask a user to open links on their desktop or laptop computers running specifically Windows OS.”
How to Stay Protected
Kaspersky advised users to remain vigilant and adopt preventive measures, including:
- Verifying unsolicited messages, links, and calls before responding.
- Avoiding the sharing of two-factor authentication (2FA) codes.
- Watching for signs of deepfake scams, such as unnatural video movements or overly generous offers.
- Rejecting camera access requests from unverified websites and avoiding uploads of personal signatures or sensitive documents.
- Using trusted security solutions like Kaspersky NEXT for corporate environments or Kaspersky Premium for individuals to block phishing attempts.
With cryptocurrency platforms continuing to be prime targets for cybercriminals, experts stress that user awareness and caution remain the strongest defenses.





