
Two Kraken employees improperly accessed support data, leading to an extortion attempt with threats to release internal system images.
Crypto exchange Kraken has revealed that it is currently facing extortion attempts from a criminal group threatening to release videos allegedly showing its internal systems with customer data.
The company said its systems had not been hacked, no funds were ever at risk and it would not comply or negotiate with the attackers.
Insider access scandal
In the latest article on The first incident was in February 2025, when a trusted source alerted Kraken to a video circulating on a criminal forum that appeared to reveal access to its customer support systems. An internal investigation quickly identified the individual responsible as a member of its support team.
The employee’s access was immediately revoked and a thorough investigation was conducted. Additional security measures have also been implemented and a limited number of affected customers have been informed. Following the incident, the exchange began working with industry partners and law enforcement agencies to tackle broader insider recruiting efforts targeting crypto companies, as well as companies in the gaming and telecommunications industries.
More recently, Percoco said the company received another report, as well as a new video showing similar unauthorized activity. Kraken re-identified the person involved, terminated their access, conducted a full investigation, and notified the small number of affected users. During the two incidents, approximately 2,000 customer accounts, which represent approximately 0.02% of its user base, were potentially accessed.
Shortly after access was revoked in these cases, the company began receiving extortion requests. The attackers threatened to distribute materials related to the two incidents to media and social media platforms if their demands were not met. Kraken reiterated that it would not pay criminals. Based on intelligence gathered during its ongoing investigations and analysis, the company said there is sufficient evidence to warrant the identification and arrest of those responsible.
The executive said Kraken is currently working with federal law enforcement in multiple jurisdictions to prosecute everyone involved. Due to the active nature of the investigation, Percoco said he could not release further details at this time, but encouraged anyone with relevant information to come forward.
You might also like:
Coinbase data breach
Coinbase also faced a major security incident in 2025, in which a hacker behind a large-scale data breach laundered millions of dollars in stolen crypto while openly mocking investigators. Unlike Kraken’s internal misuse case, the attack allegedly involved corrupt customer support staff granting unauthorized access to sensitive user data, including identities, account balances, and transaction history.
The attacker also taunted prominent blockchain investigator ZachXBT via Ethereum transaction messages and posted “L bozo” alongside a meme video. Coinbase said it refused a $20 million ransom demand related to the stolen data.
Binance Free $600 (CryptoPotato Exclusive): Use this link to create a new account and receive an exclusive $600 welcome offer on Binance (all details).
LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to sign up and open a FREE $500 position on any coin!


