
According to Kraken, two insider-related support incidents exposed limited customer data tied to about 2,000 accounts, while the exchange says its core systems were not breached and customer funds were never at risk.
Kraken said a criminal group is extorting the exchange by threatening to release internal material after two support staff members improperly accessed limited customer data. Chief Security Officer Nick Percoco said Kraken identified the incidents, revoked access, notified affected users, and received extortion demands tied to videos allegedly showing internal systems with customer information visible. The exchange said about 2,000 accounts, or roughly 0.02% of clients, were potentially viewed, but stressed that its core systems were never breached and funds were never at risk. The case highlights insider-related risks in customer support operations, where limited account information can later be used in impersonation or social-engineering attempts against users.