Crypto-exchange Kraken extorted by hackers after insider breach
嗯,用户让我用中文总结这篇文章,控制在一百个字以内,而且不需要特定的开头。首先,我需要快速浏览文章内容,抓住主要信息。 文章讲的是加密货币交易所Kraken被一个网络犯罪团伙威胁,他们试图通过泄露客户数据的视频来勒索Kraken。Kraken的首席安全官Nick Percoco提到,事件没有威胁到客户资金,是内部威胁导致的,有两个支持员工未经授权访问了有限的客户数据。Kraken拒绝支付赎金,并且已经采取措施应对,比如撤销员工访问权限、加强控制,并与执法部门合作。此外,文章还提到Coinbase也遭遇过类似事件。 接下来,我需要把这些要点浓缩到100字以内。重点包括:Kraken被勒索、内部员工泄露数据、拒绝支付、影响小、已有应对措施、以及行业内的类似事件。 可能会这样组织句子:“加密货币交易所Kraken遭网络犯罪团伙勒索,对方威胁泄露客户数据视频。事件由内部员工泄露引发,涉及少量用户数据。Kraken拒绝支付赎金,并已采取措施应对。” 这样既涵盖了主要事件、原因、后果和公司的回应。 最后检查一下字数和表达是否清晰准确。 </think> 加密货币交易所Kraken遭网络犯罪团伙勒索,对方威胁泄露客户数据视频。事件由内部员工泄露引发,涉及少量用户数据。Kraken拒绝支付赎金,并已采取措施应对。 2026-4-14 22:1:36 Author: www.bleepingcomputer.com(查看原文) 阅读量:5 收藏

Crypto-exchange Kraken extorted by hackers after insider breach

The Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data.

The company’s Chief Security Officer, Nick Percoco, stated that the incident did not put client funds at risk and involved an insider threat, with two instances of improper access to limited customer data by support employees.

Kraken says that it will not pay or negotiate with the threat actor.

Wiz

“We are currently being extorted by a criminal group threatening to release videos of our internal systems with client data shown if we do not comply with their demands,” stated Percoco.

“It’s important to start with the most important points: our systems were never breached; funds were never at risk; we will not pay these criminals; we will not ever negotiate with bad actors.”

Tweet

Kraken is a U.S.-based cryptocurrency exchange that enables millions of users across 190 countries to buy, sell, and trade digital assets such as Bitcoin, Ethereum, and 200 others.

It is considered one of the largest and most established exchanges, with a daily trading volume of hundreds of millions of U.S. dollars.

Following a “tip from a trusted source” in February 2025 about cybercriminals circulating a video demonstrating access to its client support systems, Kraken initiated an investigation and uncovered a support employee recruited by the threat actor.

More recently, Kraken received a tip about another, more recent video showing insider access to its systems.

In both cases, the company reacted quickly by revoking the employee’s access, launching investigations, and strengthening controls. Where user exposure was identified, Kraken notified affected users directly.

According to Percoco, the incident affects only about 2,000 accounts, which represents 0.02% of Kraken’s user base. For this small subset, the exposed information reportedly only concerns client support data.

Kraken stated that its investigation has gathered enough evidence to legally prosecute all involved individuals attempting to blackmail them, and the company is closely working with federal law enforcement across multiple jurisdictions towards this goal.

Insider threats and malicious recruitment are a broader problem impacting multiple industries, and especially the cryptocurrency sector.

In mid-2025, it was revealed that another major American cryptocurrency exchange, Coinbase, suffered a data breach after hackers bribed employees of an India-based customer support agency to disclose to them private client support information.

In that case, the incident impacted 70,000 customers, with Coinbase estimating the total financial damages to be $400 million.

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/security/crypto-exchange-kraken-extorted-by-hackers-after-insider-breach/
如有侵权请联系:admin#unsafe.sh