Kraken has disclosed two security incidents tied to inappropriate internal access by support staff, followed by an extortion attempt from a criminal group. According to the exchange and public comments from Chief Security Officer Nick Percoco, neither event involved a breach of Kraken’s core systems, and client funds were never at risk. The issue centered on misuse of internal support tools rather than any compromise of the company’s trading, custody, or financial control infrastructure.
Kraken said the exposed information was limited to customer support-related data, not sensitive financial controls. Once the activity was identified, the company revoked access and conducted internal reviews. In total, around 2,000 client accounts may have been viewed across both incidents, representing about 0.02% of Kraken’s global user base. The exchange added that affected users were notified directly.
The matter became more serious after the latest internal access was shut down. A criminal group allegedly claimed it possessed videos showing Kraken’s internal systems and client data, then demanded compliance under threat of public release. The group reportedly warned that the material would be distributed to media organizations and social platforms if Kraken refused to cooperate. Percoco responded publicly and made the company’s position clear: Kraken would not pay, and it would not negotiate.
How the two internal incidents unfolded at Kraken
The first incident dates back to February 2025. Kraken said it received a tip that a video was circulating on a criminal forum. That prompted an internal investigation, which identified a member of the support team as the source of the access. According to the company, it immediately revoked that person’s permissions, carried out a formal review, and implemented additional safeguards to reduce the chance of recurrence.
A second incident surfaced later after another tip referenced similar material tied to a different individual. Kraken said it again traced the source, terminated access, notified affected users, and tightened internal controls. While the company did not describe any compromise of its matching engine, wallets, or broader production infrastructure, it did acknowledge that support-side visibility into limited user information had been misused.
This distinction matters. The incidents were not described as direct external hacks into Kraken’s core systems. Instead, they involved abuse of internal support visibility. In practice, support roles often require access to account-level information for troubleshooting, identity checks, and customer case handling. That limited visibility is operationally necessary, but it can also become a target if an insider is recruited, coerced, or exploited.
The extortion attempt and Kraken’s public response
After the latest access channel was shut down, the situation escalated into extortion. Kraken said the group behind the videos began making demands, using the threat of publication as leverage. According to the exchange, the attackers claimed to hold recordings that showed internal Kraken systems alongside client data and threatened to push the material to journalists and social media if the company did not comply.
Nick Percoco rejected the pressure in direct terms. In his public statement, he said: “Our systems were never breached; funds were never at risk; we will not pay these criminals.” That message served multiple purposes. It reassured clients that the exchange’s core environment had not been penetrated, emphasized that financial assets remained safe, and signaled that Kraken would not resolve the matter through ransom or side negotiations.
Kraken also stated that it would not negotiate with the actors involved. Instead, the company said it is cooperating with law enforcement across multiple jurisdictions. Because crypto platforms operate globally, incidents of this kind can quickly cross national boundaries, making international coordination essential. Kraken further said it believes there is enough evidence to identify and pursue the individuals responsible.
Why support access remains a major insider-risk vector
The case highlights one of the most persistent security issues in digital asset markets: the insider threat. Security experts have long warned that crypto firms must defend not only against external intrusions, phishing campaigns, exploit chains, and infrastructure attacks, but also against misuse of legitimate internal access. Support teams are especially exposed because they frequently need limited visibility into user accounts in order to investigate problems and resolve tickets.
That kind of access is usually restricted, logged, and segmented, but restriction alone does not eliminate risk. If a support employee is bribed, pressured, socially engineered, or otherwise manipulated, an attacker may gain exactly the level of access needed to harvest screenshots, account details, internal workflows, or evidence that can later be weaponized in extortion or social engineering campaigns. In other words, a platform does not need to suffer a full-scale breach for meaningful damage to occur.
Kraken also pointed to a wider pattern beyond crypto. The company said broader insider recruitment efforts are targeting firms across crypto, gaming, and telecommunications. That detail suggests the threat model is expanding from classic technical intrusion to hybrid operations focused on people, incentives, and business process weaknesses. For attackers, recruiting one person with modest access can sometimes be easier than breaching a hardened production environment.
In the crypto sector, the stakes are especially high. Exchanges manage valuable assets, operate around the clock, and serve users globally. Even if internal support access does not allow direct fund movement, exposure of client support data or internal system views can still fuel follow-on fraud, targeted phishing, impersonation attempts, or reputational pressure campaigns. That is why incidents involving “limited access” still matter.
Kraken’s remediation steps and what the industry should take from this
Kraken said it continues to review internal processes, strengthen monitoring systems, and reduce access privileges where possible. Based on the company’s disclosures, its response has included identifying and shutting down the access source, revoking permissions, notifying affected users, conducting internal reviews, and adding or tightening safeguards after both incidents. Throughout its statements, Kraken repeatedly emphasized that its core infrastructure remained secure.
From an industry perspective, the episode reflects a broader security reality. Crypto platforms face two overlapping layers of risk. One comes from outside: phishing, malware, supply chain compromise, software vulnerabilities, and direct network attacks. The other comes from inside: excessive privileges, weak monitoring, poor process segmentation, or employees being coerced or recruited. Because exchanges handle high-value assets and support global online operations, they remain attractive targets for coordinated campaigns that combine technical and human tactics.
The article also referenced a separate disclosure from Galaxy Digital, the firm founded by Mike Novogratz. Galaxy reported a cybersecurity incident involving unauthorized access to an isolated development environment, while stating that no client data or funds were affected. Although that case differs from Kraken’s, the parallel is instructive: even where customer funds are untouched and core systems remain intact, companies still need strong controls around development environments, internal tooling, and access boundaries.
Kraken said it will continue cooperating with investigators and industry partners as the case develops. The exchange characterized the incidents as contained events, but it also used the disclosure to warn of a larger trend—insider-focused threats are becoming a more visible challenge across technology companies. For crypto users, this is a reminder that platform security should not be judged only by whether a company has suffered an external hack. Internal access management, auditability, transparency, and incident response discipline matter just as much.

