Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
TaskUs

TaskUs Vendor Cyber Rating & Cyber Score

taskus.com

TaskUs delivers outsourced digital services that power the companies shaping the future. By combining specialized human talent and intelligent technology, we solve complex operational challenges for global category leaders within AI, autonomous vehicles (AV), robotics, social media, financial services, healthcare, and beyond. We enable our clients to elevate their customer experience, protect their platforms, and grow their brands.


TaskUs A.I CyberSecurity Scoring

TaskUs
Company Information
Website:https://www.taskus.com/
Employees number:42,696
Number of followers:502,361
NAICS:541615
Industry Type:Outsourcing and Offshoring Consulting
Homepage:taskus.com
TaskUs Risk Score (AI oriented)
Between 550 and 599
logo
TaskUsOutsourcing and Offshoring Consulting
Updated:
01/04/2026
560/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
TaskUs Global Score (TPRM)
xxxx
logo
TaskUsOutsourcing and Offshoring Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

TaskUs
TaskUsVery Poor
Current Score
560Ca (VERY POOR)
01000
4 incidents
-69 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
302Before Incident
JULY 2026
568Before Incident
JUNE 2026
566Before Incident
MAY 2026
563Before Incident
APRIL 2026
561Before Incident
MARCH 2026
560Before Incident
FEBRUARY 2026
633Before Incident
Breach
04 Feb 2026TaskUs
TaskUs, Coinbase, Discord and Marks & Spencer: Coinbase confirms insider breach linked to leaked support tool screenshots

Coinbase Insider Breach Impacting 30 Customers

564After Incident
CRITICAL-69
MARCOIDISTAS1770173590
Coinbase Confirms Insider Breach Impacting 30 Customers in December Incident Coinbase has disclosed an insider breach involving a contractor who improperly accessed the personal data of approximately 30 customers in December. The company confirmed the incident after threat actors known as Shiny Lapsus Hunters (SLH) briefly posted screenshots of an internal support interface on Telegram, revealing customer details such as names, email addresses, phone numbers, KYC information, wallet balances, and transaction histories. The contractor, who no longer works with Coinbase, was detected by the company’s security team last year. Affected users were notified and provided with identity theft protection services, while regulators were informed as part of standard protocol. This breach is unrelated to a separate January 2025 incident involving TaskUs, an outsourcing firm that provides support services to Coinbase. The screenshots shared by SLH suggest the group may have obtained the data through an insider or by circulating stolen information among threat actors. SLH has previously claimed to have bribed insiders at other firms, including CrowdStrike, to gain access to internal systems. Rising Threats to Business Process Outsourcing (BPO) Firms The incident highlights a growing trend of threat actors targeting BPO companies third-party firms handling customer support, IT services, and account management for organizations. Since BPO employees often have access to sensitive systems and data, they have become prime targets for attacks. Common tactics include: - Bribing insiders to steal or share customer information, as seen in the Coinbase and TaskUs breaches. - Social engineering support staff to gain unauthorized access, such as the Clorox breach, where attackers impersonated an employee to compromise a Cognizant help desk agent, leading to a $380 million lawsuit. - Compromising BPO employee accounts to access customer data, as in Discord’s October breach, where a support agent’s account at an outsourced provider was used to extract data from 5.5 million users. Recent attacks on retailers like Marks & Spencer and Co-op have also involved social engineering against support personnel, prompting the U.K. government to issue guidance on mitigating such threats. The shift toward targeting BPOs reflects a broader strategy by threat actors to exploit third-party access rather than directly breaching corporate networks.
INCIDENT DETAILS -
TYPE
Insider Threat
MOTIVATION
Data Theft, Financial Gain
IMPACT
Data Compromised: Personal data (names, email addresses, phone numbers, KYC information, wallet balances, transaction histories)Systems Affected: Internal support interfaceBrand Reputation Impact: YesIdentity Theft Risk: Yes
DATA BREACH
Personal Identifiable Information (PII)KYC InformationTransaction HistoriesWallet BalancesNumber Of Records Exposed: 30Sensitivity Of Data: HighData Exfiltration: Yes (via Telegram screenshots)Personally Identifiable Information: Yes
JANUARY 2026
633Before Incident
DECEMBER 2025
631Before Incident
NOVEMBER 2025
629Before Incident
OCTOBER 2025
626Before Incident
SEPTEMBER 2025
624Before Incident
JUNE 2025
439Before Incident
Breach
03 Jun 2025TaskUs
Coinbase

Data Breach at Coinbase

243After Incident
CRITICAL-196
COI739060625
A data breach at Coinbase, facilitated by bribed customer support representatives from outsourcing firm TaskUs, resulted in the theft of sensitive user data including names, emails, partial financial information, SSN, transaction history, and ID document scans. The breach affected nearly 70,000 customers and was discovered after an employee was caught capturing photos of her computer screen. The threat actors demanded a $20,000,000 ransom to not publish the stolen data. Coinbase estimated the incident would cause losses of up to $400 million.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Financial Loss: Up to $400 millionnamesemailspartial financial informationSSNtransaction historyID document scansSystems Affected: Customer support systems
DATA BREACH
namesemailspartial financial informationSSNtransaction historyID document scansNumber Of Records Exposed: 70,000Sensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
SEPTEMBER 2024
575Before Incident
Breach
01 Sep 2024TaskUs
Coinbase

Coinbase Data Breach via TaskUs Outsourcing Firm

379After Incident
CRITICAL-196
COI5902859091725
In May, Coinbase disclosed a major data breach where hackers, aided by rogue employees at its outsourcing partner TaskUs, stole personal data of 69,000+ customers, including Social Security numbers and bank details. The breach originated from Ashita Mishra, a TaskUs employee in India, who systematically exfiltrated data (up to 200 customer records daily) from September 2024 to January 2025, selling it for $200 per screenshot to a criminal collective called ‘The Comm’—comprising teenagers and young hackers. The stolen data was used to impersonate Coinbase staff, tricking victims into transferring cryptocurrency. The breach, initially downplayed by Coinbase (which cited a December 2024 timeline), involved internal collusion, including team leaders and HR staff at TaskUs. Coinbase faces $400M in losses, regulatory scrutiny, and class-action lawsuits, while TaskUs fired 226 employees in Indore and dismantled its investigative HR team, allegedly to conceal the breach’s scale. The incident marks Coinbase’s worst breach in its history, exposing systemic vulnerabilities in third-party vendor security and internal oversight.
INCIDENT DETAILS -
TYPE
data breachinsider threatsocial engineeringfraud
MOTIVATION
financial gain
IMPACT
Financial Loss: $400 million (estimated cost to Coinbase)Social Security numbersbank account informationcustomer account detailsTaskUs internal systems (Indore, India service center)Coinbase customer support databasestermination of 226 TaskUs employeessevered ties with involved personnelinvestigation disruptionsCustomer Complaints: multiple (class-action lawsuits filed)severe damage due to largest breach in Coinbase historypublic distrust in outsourcing securitylegal scrutinyclass-action lawsuits (e.g., Greenbaum Olbrantz)regulatory investigationspotential finesIdentity Theft Risk: high (SSNs and bank details exposed)Payment Information Risk: high (bank account information compromised)
DATA BREACH
personally identifiable information (PII)financial dataaccount credentialsNumber Of Records Exposed: 69,000+Sensitivity Of Data: high (SSNs, bank accounts)Data Exfiltration: yes (via photos of customer accounts, sold to hackers)screenshots/photos of customer accountsdatabasesSocial Security numbersnamesbank account details
JUNE 2024
754Before Incident
Breach
16 Jun 2024TaskUs
TaskUs

Systemic Security Failures and Data Breach at TaskUs Affecting Coinbase Customer Data

577After Incident
CRITICAL-177
TAS4962149091725
The breach involved a coordinated criminal bribery scheme within TaskUs’s India operations, where employees were allegedly bribed to photograph and leak sensitive Coinbase customer account data to external criminals. The conspiracy expanded beyond front-line staff, leading to the dismissal of around 300 employees in January 2025. TaskUs reportedly concealed the breach’s scope, silenced whistleblowers, and fired HR personnel investigating the incident. Despite internal awareness, the company denied any material breach in regulatory filings (including a February 2025 Form 10-K) and proceeded with a $1.6 billion buyout by Blackstone before Coinbase publicly disclosed the incident in May. The breach originated in late 2024, affecting less than 1% of Coinbase’s monthly transacting users, with estimated losses reaching $400 million. Coinbase reimbursed victims, severed ties with TaskUs, and offered a $20 million reward for information leading to arrests, refusing to pay ransom demands.
INCIDENT DETAILS -
TYPE
Data BreachInsider ThreatSocial EngineeringBribery Scheme
MOTIVATION
Financial Gain (Data Theft for Fraud/Resale)
IMPACT
Financial Loss: $400 million (estimated total loss)Coinbase Customer Account InformationPersonally Identifiable Information (PII)Termination of 300+ TaskUs EmployeesEnd of Coinbase-TaskUs PartnershipHR Personnel Fired During InvestigationCustomer Complaints: Class Action Lawsuit Filed (Southern District of New York)Negative Publicity for TaskUs and CoinbaseAllegations of Concealment and Non-DisclosureLoss of Trust in Outsourcing SecurityClass Action LawsuitPotential Regulatory Violations for Non-DisclosureIdentity Theft Risk: High (Sensitive Account Information Compromised)
DATA BREACH
Customer Account InformationSensitive Account Details (Photographed)Sensitivity Of Data: High (PII, Account Access Details)Data Exfiltration: Yes (Physical Theft via Photographs, Shared with Criminals)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for TaskUs ?
?
What was TaskUs's A.I Rankiteo Cyber Score in July 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in June 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in May 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in April 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in March 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in February 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in January 2026 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in December 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in November 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in October 2025 ?
?
What was TaskUs's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on TaskUs's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with TaskUs ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view TaskUs's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
TaskUs Cyber Scoring History | Rankiteo