Kraken Faces Insider Data Access Abuse and Extortion Pressure Over Support Tool Incidents

Kraken Faces Insider Data Access Abuse and Extortion Pressure Over Support Tool Incidents

N
News Editor 01
2026-07-03 19:30:14
Crypto exchange Kraken disclosed two insider-related security incidents tied to support staff access to limited customer data, later followed by an extortion attempt by a criminal group. The company said its core systems were never breached and that client funds were never at risk. Across both cases, around 2,000 accounts may have been viewed, representing about 0.02% of Kraken’s global user base. The first incident dates back to February 2025, when a tip about a video circulating on a criminal forum led the company to identify a support team member as the source of improper access. A later tip pointed to similar material linked to a different individual, prompting another internal response. Kraken says affected users were notified, permissions were revoked, and internal controls were tightened. Chief Security Officer Nick Percoco stated that the attackers claimed to possess videos showing internal systems and client data and threatened to publish them unless Kraken complied. He added that the exchange would not pay or negotiate. Kraken is now cooperating with law enforcement across multiple jurisdictions and says the case reflects a broader pattern of insider-focused threats affecting crypto, gaming, and telecommunications firms.
Krakenexchange securityinsider threatcustomer data accessextortion attemptsupport toolscrypto risk management

Crypto exchange Kraken has disclosed two security incidents involving insider misuse of internal support access, followed by an extortion attempt by a criminal group. According to the company’s statement and public comments from Chief Security Officer Nick Percoco, the issue did not involve a breach of Kraken’s core trading or custody systems. Instead, both cases were tied to inappropriate access to internal support tools that provided limited visibility into certain customer data.

Kraken stressed that no client funds were ever at risk and that its main infrastructure remained secure throughout both incidents. The company framed the problem as one of improper internal access rather than an external compromise of the exchange itself. Once the activity was identified, the relevant permissions were revoked. The attackers then escalated by claiming they held videos showing internal systems containing customer information and demanding that Kraken comply with their terms or face public exposure.

The exchange said roughly 2,000 customer accounts may have been viewed across the two incidents, equal to around 0.02% of its global user base. Kraken added that affected customers were notified and that the exposed information was limited to support-related data rather than sensitive financial controls. In other words, the company acknowledges that inappropriate account visibility occurred, but maintains that the incidents did not develop into a theft-of-funds scenario or a compromise of core account control mechanisms.

How the two insider access incidents unfolded at Kraken

The first incident dates back to February 2025. Kraken said it received a tip about a video circulating on a criminal forum. An internal investigation traced the access to a member of the support team. After identifying the source, the company revoked permissions, reviewed the matter internally, and implemented additional safeguards intended to reduce the likelihood of similar abuse in the future.

A second case surfaced later, again after Kraken received a tip referencing comparable material. This time, the content was linked to a different individual. The company said it once more identified the source of the access, terminated the relevant permissions, notified impacted users, and tightened internal controls. The repetition of the pattern suggests a broader access governance problem around support tooling rather than a one-off anomaly.

What connects both incidents is that they were not described as traditional hacks against the exchange’s core systems. Instead, they involved support-side visibility into customer accounts being used inappropriately. On many crypto platforms, support roles require some degree of account visibility for troubleshooting, case management, or identity-related assistance. Even when such access is limited, any internal system that exposes user-level information can become an attractive target for coercion, recruitment, or exploitation.

How the extortion pressure escalated and Kraken’s response

The situation escalated after the latest unauthorized access was shut down. Kraken said the group behind the videos issued extortion demands and threatened to distribute the material to media outlets and social platforms. That detail matters because the leverage in this case was not based on stolen funds, but on reputational pressure built around recordings of internal systems and customer-related data.

Nick Percoco responded publicly in firm terms. He said, “Our systems were never breached; funds were never at risk; we will not pay these criminals,” and added that Kraken would not negotiate with the actors involved. The statement served two purposes. First, it underscored Kraken’s position that the incidents were contained internal access abuses rather than a compromise of core infrastructure. Second, it made clear that the company would reject ransom-style demands rather than attempt to quietly settle the matter.

Kraken also emphasized that affected users had already been notified and that internal monitoring, process reviews, and access restrictions were being strengthened. This distinction is central to how the case should be understood. The company is not denying that customer data was viewed improperly. Instead, it is drawing a boundary around the incident: support-related data may have been exposed, but financial control systems were not, and client funds remained unaffected.

Law enforcement cooperation and the wider insider threat problem

Kraken said it is cooperating with law enforcement in multiple jurisdictions and believes there is sufficient evidence to identify and pursue those responsible. Because the case appears to involve criminal forums, recorded materials, attempted extortion, and potentially cross-border actors, a multi-jurisdictional response is significant. It indicates that this is more than a simple case of internal policy violation and may involve a broader organized criminal component.

The exchange also pointed to wider insider recruitment efforts targeting firms not only in crypto, but also in gaming and telecommunications. That observation matters because it places the incident within a larger cross-industry pattern. For attackers, directly breaching a major technology platform can be costly, technically difficult, and uncertain. Recruiting, coercing, or exploiting insiders with limited but useful access may be a more efficient route.

Security experts have long warned that insider threats remain especially serious in digital asset markets. Crypto platforms combine high-value assets with global, always-on operations and large support workloads involving account issues, identity checks, and troubleshooting. That means support staff often need restricted visibility into user accounts. If permission design, audit logging, detection systems, or employee screening fall short, those support paths can become abuse points.

Kraken’s disclosures reinforce the importance of least-privilege access design. In practice, that means not eliminating support access entirely, but limiting access to the smallest necessary scope, for the shortest possible time, with strong traceability and oversight. For exchanges, internal support tools are operationally necessary, but they can also become one of the most sensitive security surfaces inside the organization.

From Kraken to Galaxy Digital: a broader industry security reality

The Kraken case arrives at a time when the crypto industry continues to face pressure from both external attacks and internal vulnerabilities. High-value assets, global user bases, 24/7 operations, and complex identity and transaction workflows create a demanding security environment. Much of the public conversation still focuses on wallet breaches, smart contract exploits, bridge hacks, or private key failures. However, cases like this show that internal access governance can be just as important.

In a separate disclosure mentioned alongside Kraken’s case, Galaxy Digital, the firm founded by Mike Novogratz, reported a cybersecurity incident involving unauthorized access to an isolated development environment. Galaxy Digital said no client data or funds were affected. While the two incidents are different, together they illustrate the range of threats now facing digital asset firms, from production systems and development environments to insider access and reputational extortion attempts.

Kraken said it will continue cooperating with investigators and industry partners as the case develops. The company characterized the incidents as contained events while also warning of a wider pattern of insider-focused threats facing technology firms. For users, that framing matters. Even when a platform avoids direct financial loss, internal data access controls, employee privilege management, auditability, and anomaly detection remain essential measures of whether an exchange is truly security-mature.

Overall, the significance of Kraken’s disclosure is not limited to the question of whether the exchange was “hacked.” The more important issues are how insider misuse was detected, how extortion pressure was handled, how the scope of customer data exposure was defined, and how law enforcement is being engaged. No funds were reported lost, but the episode is a reminder that in crypto, security depends not only on defending against outside attackers, but also on controlling internal tools, employee access, and operational processes with equal rigor.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.