Kraken Says Extortion Attempt Affects About 2,000 Accounts

Kraken Says Extortion Attempt Affects About 2,000 Accounts

According to Kraken, two insider-related support incidents exposed limited customer data tied to about 2,000 accounts, while the exchange says its core systems were not breached and customer funds were never at risk.

Fact Check
The statement is closely supported by the fetched CoinDesk article, which says Kraken described two insider-related improper-access incidents affecting about 2,000 accounts, explicitly stated its systems were never breached, and said client funds were never at risk. The same article also reports the 0.02% figure, though that specific percentage is attributed to 'a person with knowledge of the matter' rather than a directly quoted Kraken statement. The Odaily link traced back to the same CoinDesk article, adding no independent support. Because the linked X posts were not fetchable and I could not directly validate a Kraken primary statement in this run, the claim is best rated likely true rather than confirmed with high confidence.
    Reference1
Summary

Kraken said a criminal group is extorting the exchange by threatening to release internal material after two support staff members improperly accessed limited customer data. Chief Security Officer Nick Percoco said Kraken identified the incidents, revoked access, notified affected users, and received extortion demands tied to videos allegedly showing internal systems with customer information visible. The exchange said about 2,000 accounts, or roughly 0.02% of clients, were potentially viewed, but stressed that its core systems were never breached and funds were never at risk. The case highlights insider-related risks in customer support operations, where limited account information can later be used in impersonation or social-engineering attempts against users.

Terms & Concepts
  • Crypto exchange: A platform where users buy, sell, and trade digital assets such as Bitcoin and other cryptocurrencies.
  • Extortion: A criminal act that uses threats, such as releasing sensitive information, to demand money or compliance.
  • Insider access: Internal employee or contractor access that can be misused to view or handle data without authorization.