The cyber-extortion group known as Coinbase Cartel has listed Tower Insurance on its leak site, claiming the New Zealand insurer has been targeted as part of an ongoing ransomware-extortion campaign.
At the time of writing, Tower Insurance has not publicly confirmed the claim, any data theft, or contact with the threat actor. The listing should therefore be treated as an unverified allegation until further evidence or an official statement becomes available.
Who is Coinbase Cartel?
Coinbase Cartel is a cyber-extortion threat actor first observed in September 2025. Unlike traditional ransomware groups that primarily encrypt victims’ systems, Coinbase Cartel is understood to focus on data theft and extortion.
The group threatens to publish or sell stolen information unless victims agree to its demands. Reportedly, victims are given approximately 48 hours to make contact, followed by a 10-day period to pay or negotiate.
The group operates a dark-web leak site and has used staged disclosures as part of its pressure campaign. This can involve publishing limited samples of allegedly stolen data before escalating to a larger disclosure if demands are not met.
More than 60 victims have reportedly been claimed by the group across sectors including healthcare, technology, transportation, finance, and telecommunications.
Possible links to other threat groups
Various cybersecurity analysts have suggested that Coinbase Cartel may include affiliates or individuals associated with groups such as ShinyHunters, Scattered Spider, and Lapsus$.
The group is also reportedly developing ransomware targeting VMware ESXi environments. If confirmed, this could represent a shift from primarily data-theft-based extortion toward a more traditional double-extortion model, combining data theft with system encryption.
Infostealer credentials and initial access
Coinbase Cartel is also known for allegedly making use of credentials obtained through infostealers.
Stolen credentials can provide attackers with a relatively straightforward path into organisations, particularly when credentials are reused or protected by weak authentication controls. Public-facing applications and VPN portals can become attractive targets when valid credentials have already been compromised.
This makes the monitoring of stolen corporate credentials an important component of defensive security, particularly for organisations with internet-facing remote-access infrastructure.
Tower Insurance credentials appearing online
There have also been reports of tower.co.nz-related credentials appearing on dark-web forums during the past month.
However, it is currently unclear whether these credentials are newly obtained, associated with the alleged Coinbase Cartel activity, or simply older credentials being recirculated. The presence of credentials online does not by itself establish that Tower Insurance was breached or that the credentials were obtained as part of this incident.
At this stage, there is no publicly confirmed evidence linking those credentials to the Coinbase Cartel claim.
What happens next?
The key question is whether Coinbase Cartel can substantiate its claim with genuine Tower Insurance data.
Threat-actor leak sites are not independently verified sources, and listings can contain misleading, exaggerated, or fraudulent claims. Confirmation would require evidence such as validated samples of sensitive information, forensic findings, or an official statement from Tower Insurance.
Organisations potentially affected by similar activity should consider reviewing exposed credentials, monitoring authentication logs, investigating unusual VPN or remote-access activity, and ensuring that multi-factor authentication is enabled across externally accessible services.
This is a developing story. The Coinbase Cartel listing and any associated claims should be considered unverified unless independently confirmed by Tower Insurance or credible cybersecurity researchers.