Kraken recently confirmed two security incidents involving unauthorized access by support staff to limited client data, followed by an extortion attempt from a criminal group. The exchange emphasized that no funds were compromised and no core systems were breached, with incidents limited to internal support tools rather than trading infrastructure.
Details of the Security Incidents
The first incident occurred in February 2025 after Kraken received information about a video circulating on criminal forums. An internal investigation revealed that a support team member had inappropriately accessed client data. The company revoked the individual's permissions and implemented additional safeguards.
A second incident followed similar patterns, involving a different support staff member. Upon discovery, Kraken terminated access, notified affected users, and strengthened internal controls. Approximately 2,000 client accounts—roughly 0.02% of Kraken's user base—were potentially viewed across both incidents, with exposure limited to support data rather than financial controls.
Following the shutdown of unauthorized access, the criminal group escalated their demands, threatening to distribute videos showing internal systems with client data to media and social platforms. Chief Security Officer Nick Percoco stated firmly: "Our systems were never breached; funds were never at risk; we will not pay these criminals."
Implications for Crypto Industry Professionals
This incident highlights growing insider threat risks across the cryptocurrency sector, particularly for professionals in customer support and operations roles. Security experts note that support positions often require account visibility for troubleshooting, creating potential vulnerabilities that malicious actors actively exploit through coercion or recruitment.
Kraken reports broader insider recruitment campaigns targeting firms across crypto, gaming, and telecommunications sectors. The exchange is collaborating with law enforcement across multiple jurisdictions and believes sufficient evidence exists to identify those responsible.
For crypto professionals, these incidents underscore the importance of robust access controls, continuous monitoring systems, and comprehensive security training. Companies may increasingly scrutinize hiring practices and implement stricter protocols for roles with data access. Galaxy Digital separately disclosed a cybersecurity incident involving an isolated development environment, suggesting industry-wide attention to both external and internal security vectors continues to intensify.


