Full story
Kraken Extortion
Kraken is facing an extortion attempt by a criminal group threatening to release videos showing access to internal systems containing client data.
“Our systems were never breached; funds were never at risk; we will not pay these criminals; we will not ever negotiate with bad actors”
The company identified and shut down two instances of inappropriate access tied to individuals within its support team.

Approximately 2,000 accounts were affected, about 0.02% of its client base.
Chief Security Officer Nick Percoco said, Our systems were never breached; funds were never at risk; we will not pay these criminals.
Kraken has been working with industry partners and law enforcement to investigate broader insider recruitment efforts.
Insider Access
The extortion attempt stemmed from improper access by individuals linked to Kraken's customer service operation.
The accessed data was limited to client support information, far removed from core infrastructure.

Kraken notified all potentially affected clients and revoked access for the individuals involved.
Percoco described the attack as part of a rising pattern of internal infiltration + social engineering.
Human vulnerabilities remain a persistent risk in crypto despite technical safeguards.
Response and Consequences
Kraken refused to pay the ransom and escalated the matter to law enforcement.
“We will not pay these criminals; we will not ever negotiate with bad actors”
The exchange believes it has sufficient evidence to identify and arrest those responsible.
The incident affected roughly 0.02% of Kraken's 13 million registered users.
No customer funds were ever at risk and core infrastructure remained secure.
Kraken's response represents a mature approach to inevitable security challenges.
