A little known extortion brand that calls itself Coinbase Cartel is trying to punch above its weight, listing a run of blue chip company names on its dark web leak site. On 20 July 2026 the crew added the US heavy equipment maker Caterpillar and the global commercial real estate firm Colliers to the page it uses to pressure victims into paying.
A ransomware leak site is the public shaming page a crew runs to squeeze organizations it says it has hacked: names go up, a countdown starts, and stolen files are threatened or released if no ransom is paid. Being listed is not the same as a confirmed breach. None of the companies named has publicly acknowledged an incident, and leak site claims are frequently inflated, tied to a small subsidiary or third party supplier rather than the headline brand, or built on recycled data from an older intrusion.
What Coinbase Cartel is claiming
The choice of targets fits a familiar playbook: a smaller or newer crew names the most recognizable brands it can in order to buy attention and negotiating leverage. Days earlier, on 15 July, the same group listed Panasonic Avionics, the in flight entertainment and connectivity supplier used by many of the world's airlines. Alongside those marquee names the group has also posted a string of lower profile business services and manufacturing victims.
IntelFusions tracks the group on its Coinbase Cartel profile. Despite the crypto flavored name, there is no public evidence tying the brand to the Coinbase exchange or to any specific cryptocurrency operation, and the label appears chosen mostly for shock value.
What is known and not known
The crew has not published verifiable proof of the scale of any of these intrusions, and has not disclosed how it says it gained access, how much data it took, or what ransom it is demanding. Until a named company confirms an incident or leaked samples are validated, each listing should be treated as an unverified allegation rather than an established fact. IntelFusions assesses with moderate confidence that at least some of these entries are opportunistic name grabs designed to maximize visibility for a brand still building its reputation.
Why it matters
Leak sites are growing more crowded as new and rebranded crews compete for affiliates and attention, a trend covered in our roundup of smaller ransomware brands crowding the leak sites. For defenders the noise is a problem in itself: a single high profile listing can trigger customer, regulator and press inquiries long before anyone knows whether real data was taken.
What you should do
Organizations that see their name on a leak site, or that depend on a named supplier, should move quickly to confirm or rule out an intrusion rather than wait for the countdown. Preserve logs, engage incident response, and look for unusual remote access, new accounts and large outbound data transfers. Verify whether any exposed data belongs to your environment or a partner's, reset exposed credentials, and review third party and vendor access, since extortion crews increasingly reach large brands through their smaller suppliers.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.