Kraken Refuses Ransom After Insider Misuse Exposed 2,000 Client Accounts
DB
Dana Blackwell
crypto exchange hack · Apr 14, 2026
Source: DojiDoji Data Terminal
Approximately 2,000 Kraken client accounts were potentially viewed after two employees in the support team misused internal systems to access client support data. The exposure affected 0.02% of the exchange's clients.
The incident resulted from two separate access events. The first occurred in February 2025, when a video of the internal systems was shared on a criminal forum. A second, similar event followed. In both cases, Kraken identified the internal sources, revoked their access and notified the affected users.
Following the termination of access, a criminal group threatened to release videos of the internal systems and client data to media outlets and social media platforms if the company did not comply with payment demands. Kraken refused to pay the ransom.
Chief Security Officer Nick Percoco stated that the exchange's core systems were never breached and no customer funds were at risk. The company is now collaborating with industry partners to disrupt insider recruitment efforts targeting crypto, gaming, and telecommunications organizations.
Kraken has provided evidence to federal law enforcement across multiple jurisdictions to support the identification and arrest of those responsible.