Coinbase Cartel is a data-theft extortion identity observed on data leak sites. Public sources primarily describe it as data extortion; there is insufficient evidence to classify it as a family of ransomware with confirmed encryption.
In March 2026, the Venezuelan pharmaceutical supplier Drogueria Nena, C.A. (Dronena) was listed on the leak site operated by the threat actor Coinbase Cartel. The incident was recorded by multiple ransomware and data breach tracking platforms, with a discovery date of March 30, 2026. However, the threat actor’s website explicitly stated, “No leaked information is available yet,” making it unclear whether any data was actually exfiltrated or leaked, and the exact nature of the initial network compromise remains unknown.