Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
TaskUs

TaskUs Vendor Cyber Rating & Cyber Score

taskus.com

TaskUs is a different breed of BPO. We are a collective of highly capable humans, who understand how to deploy technology and data to best serve your purpose. From Digital CX to Trust & Safety, AI Services, Risk + Response, Consulting, and anything in between, we consider ourselves responsible for protecting our partners’ interests and supporting their long term success through innovation and technology - powered by ridiculously smart people. TaskUs partners with the world’s most innovative and disruptive brands to protect what matters most and to thrive in an ever changing world.


TaskUs A.I CyberSecurity Scoring

TaskUs
Company Information
Website:https://www.taskus.com/
Employees number:38,715
Number of followers:433,428
NAICS:541615
Industry Type:Outsourcing and Offshoring Consulting
Homepage:taskus.com
TaskUs Risk Score (AI oriented)
Between 550 and 599
logo
TaskUsOutsourcing and Offshoring Consulting
Updated:
01/04/2026
560/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
TaskUs Global Score (TPRM)
xxxx
logo
TaskUsOutsourcing and Offshoring Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

TaskUs
TaskUsVery Poor
Current Score
560Ca (VERY POOR)
01000
2 incidents
-69 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
566Before Incident
MAY 2026
563Before Incident
APRIL 2026
561Before Incident
MARCH 2026
560Before Incident
FEBRUARY 2026
633Before Incident
Breach
04 Feb 2026TaskUs
TaskUs, Coinbase, Discord and Marks & Spencer: Coinbase confirms insider breach linked to leaked support tool screenshots

Coinbase Insider Breach Impacting 30 Customers

564After Incident
CRITICAL-69
MARCOIDISTAS1770173590
Coinbase Confirms Insider Breach Impacting 30 Customers in December Incident Coinbase has disclosed an insider breach involving a contractor who improperly accessed the personal data of approximately 30 customers in December. The company confirmed the incident after threat actors known as Shiny Lapsus Hunters (SLH) briefly posted screenshots of an internal support interface on Telegram, revealing customer details such as names, email addresses, phone numbers, KYC information, wallet balances, and transaction histories. The contractor, who no longer works with Coinbase, was detected by the company’s security team last year. Affected users were notified and provided with identity theft protection services, while regulators were informed as part of standard protocol. This breach is unrelated to a separate January 2025 incident involving TaskUs, an outsourcing firm that provides support services to Coinbase. The screenshots shared by SLH suggest the group may have obtained the data through an insider or by circulating stolen information among threat actors. SLH has previously claimed to have bribed insiders at other firms, including CrowdStrike, to gain access to internal systems. Rising Threats to Business Process Outsourcing (BPO) Firms The incident highlights a growing trend of threat actors targeting BPO companies third-party firms handling customer support, IT services, and account management for organizations. Since BPO employees often have access to sensitive systems and data, they have become prime targets for attacks. Common tactics include: - Bribing insiders to steal or share customer information, as seen in the Coinbase and TaskUs breaches. - Social engineering support staff to gain unauthorized access, such as the Clorox breach, where attackers impersonated an employee to compromise a Cognizant help desk agent, leading to a $380 million lawsuit. - Compromising BPO employee accounts to access customer data, as in Discord’s October breach, where a support agent’s account at an outsourced provider was used to extract data from 5.5 million users. Recent attacks on retailers like Marks & Spencer and Co-op have also involved social engineering against support personnel, prompting the U.K. government to issue guidance on mitigating such threats. The shift toward targeting BPOs reflects a broader strategy by threat actors to exploit third-party access rather than directly breaching corporate networks.
INCIDENT DETAILS -
TYPE
Insider Threat
MOTIVATION
Data Theft, Financial Gain
IMPACT
Data Compromised: Personal data (names, email addresses, phone numbers, KYC information, wallet balances, transaction histories)Systems Affected: Internal support interfaceBrand Reputation Impact: YesIdentity Theft Risk: Yes
DATA BREACH
Personal Identifiable Information (PII)KYC InformationTransaction HistoriesWallet BalancesNumber Of Records Exposed: 30Sensitivity Of Data: HighData Exfiltration: Yes (via Telegram screenshots)Personally Identifiable Information: Yes
JANUARY 2026
633Before Incident
DECEMBER 2025
631Before Incident
NOVEMBER 2025
629Before Incident
OCTOBER 2025
626Before Incident
SEPTEMBER 2025
624Before Incident
AUGUST 2025
621Before Incident
JULY 2025
618Before Incident
JUNE 2024
754Before Incident
Breach
16 Jun 2024TaskUs
TaskUs

Systemic Security Failures and Data Breach at TaskUs Affecting Coinbase Customer Data

577After Incident
CRITICAL-177
TAS4962149091725
The breach involved a coordinated criminal bribery scheme within TaskUs’s India operations, where employees were allegedly bribed to photograph and leak sensitive Coinbase customer account data to external criminals. The conspiracy expanded beyond front-line staff, leading to the dismissal of around 300 employees in January 2025. TaskUs reportedly concealed the breach’s scope, silenced whistleblowers, and fired HR personnel investigating the incident. Despite internal awareness, the company denied any material breach in regulatory filings (including a February 2025 Form 10-K) and proceeded with a $1.6 billion buyout by Blackstone before Coinbase publicly disclosed the incident in May. The breach originated in late 2024, affecting less than 1% of Coinbase’s monthly transacting users, with estimated losses reaching $400 million. Coinbase reimbursed victims, severed ties with TaskUs, and offered a $20 million reward for information leading to arrests, refusing to pay ransom demands.
INCIDENT DETAILS -
TYPE
Data BreachInsider ThreatSocial EngineeringBribery Scheme
MOTIVATION
Financial Gain (Data Theft for Fraud/Resale)
IMPACT
Financial Loss: $400 million (estimated total loss)Coinbase Customer Account InformationPersonally Identifiable Information (PII)Termination of 300+ TaskUs EmployeesEnd of Coinbase-TaskUs PartnershipHR Personnel Fired During InvestigationCustomer Complaints: Class Action Lawsuit Filed (Southern District of New York)Negative Publicity for TaskUs and CoinbaseAllegations of Concealment and Non-DisclosureLoss of Trust in Outsourcing SecurityClass Action LawsuitPotential Regulatory Violations for Non-DisclosureIdentity Theft Risk: High (Sensitive Account Information Compromised)
DATA BREACH
Customer Account InformationSensitive Account Details (Photographed)Sensitivity Of Data: High (PII, Account Access Details)Data Exfiltration: Yes (Physical Theft via Photographs, Shared with Criminals)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for TaskUs ?
?
What was TaskUs's A.I Rankiteo Cyber Score in May 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in April 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in March 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in February 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in January 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in December 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in November 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in October 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in September 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in August 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on TaskUs's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with TaskUs ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view TaskUs's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?