TL;DR: Crypto exchange Kraken disclosed on April 13, 2026 that a criminal group recruited two of its support employees to access internal systems, recorded video footage of customer data screens, and is now extorting the company to keep the videos quiet. About 2,000 customer accounts (0.02% of Kraken’s user base) were viewed. No funds were stolen. Kraken says it won’t pay. But the bigger story is what this reveals: there’s now an active darknet marketplace for buying insider access at crypto exchanges, banks, telecom companies, and gaming firms. Check Point Research found job ads specifically naming Coinbase, Binance, and Kraken, offering $3,000 to $15,000 per employee willing to sell access.
Two Employees. Two Videos. One Extortion Demand.
In February 2025, Kraken received a tip from a “trusted source” about a video circulating on a criminal forum. The video showed someone navigating Kraken’s internal customer management systems: the kind of screens that display account details, personal information, and support history.[1]
Kraken investigated and traced the access to a support team employee who’d been recruited by the criminal group. They revoked access and launched an investigation.
Then it happened again. A second, more recent video surfaced showing similar insider access from another support employee. Same pattern: recruitment, unauthorized access, screen recording.
Shortly after Kraken cut off the second employee’s access, the extortion demands started. The criminal group threatened to distribute both videos to media outlets and on social media unless Kraken paid up.[2]
Kraken’s Chief Security Officer Nick Percoco was blunt: “Our systems were never breached; funds were never at risk; we will not pay these criminals; we will not ever negotiate with bad actors.”[3]
Who Got Exposed
Approximately 2,000 customer accounts were potentially viewed across both incidents. That’s 0.02% of Kraken’s total user base. The company says the access was limited to support-level data: the kind of information a customer service agent would normally see when handling a ticket.[1]
Kraken notified affected customers directly. No funds were stolen or moved. The company says no full system penetration occurred: the insiders only had access to what their support roles allowed them to see.
That’s the official line, and it might be true. But it also highlights the problem: even “limited” support access at a crypto exchange means names, email addresses, account activity, and potentially KYC documents like passport scans and government IDs. That’s enough for targeted phishing, SIM swaps, or identity theft.
The Darknet Job Board for Insiders
Here’s where this story gets worse.
Kraken isn’t an isolated case. In December 2025, Check Point Research published findings on a growing darknet marketplace for insider access. Criminal groups are running what amount to job boards: posting ads on Russian-language forums and Telegram channels with hundreds of members, specifically recruiting employees at crypto exchanges, banks, and telecom companies.[4]
The ads name targets. Coinbase, Binance, Kraken, and Gemini all appeared in recent listings. The pay structure is straightforward:
- $3,000–$15,000 for one-time access or a specific data pull
- Five- to six-figure payouts for ongoing relationships
- Stolen datasets available for purchase: one ad offered 37 million user records from a crypto exchange for $25,000
One recruitment ad told potential insiders to “escape the endless work cycle” by partnering with cybercriminals. All payments are in cryptocurrency (Bitcoin and Monero) to maintain anonymity.[4]
This isn’t hacking. This is HR for organized crime.
Why Crypto Exchanges Are Especially Vulnerable
Banks have decades of insider threat programs, compartmentalized access, and regulatory frameworks requiring employee monitoring. Crypto exchanges are newer, faster-growing, and often built with security focused outward (protecting against hacks) rather than inward.
Support teams at exchanges typically have access to:
- Customer names, emails, and phone numbers
- KYC verification documents (passports, driver’s licenses, selfies)
- Account balances and transaction histories
- Support ticket contents, which often include sensitive financial details
A support agent making $50,000 a year being offered $15,000 for a single data pull is doing the math whether they should or not. When the offer comes through an encrypted Telegram channel and payment is in Monero, the perceived risk drops.
Kraken says it’s working with “industry partners and law enforcement to investigate broader insider recruitment efforts targeting crypto, gaming and telecommunications firms.” Percoco says they have “sufficient evidence to identify and apprehend those responsible.”[2]
A Pattern, Not an Anomaly
The insider threat in tech isn’t new, but the industrialization of it is. Criminal groups aren’t just finding willing insiders by accident: they’re running structured recruitment campaigns across multiple industries.
Check Point’s research found that a significant portion of insider-related activity targets the financial sector specifically. The telecoms angle matters too: a compromised telecom employee can intercept SMS-based two-factor authentication codes, enabling SIM swap attacks that drain crypto wallets.[4]
Put the pieces together: recruit an insider at a crypto exchange to identify high-value accounts, recruit a telecom insider to intercept 2FA codes, and you’ve got a coordinated attack chain that never touches a firewall.
What Kraken Users Should Do Now
- Switch to hardware-based 2FA. Use a YubiKey or similar hardware security key instead of SMS or authenticator app codes. Hardware keys can’t be intercepted by SIM swaps.
- Check your email for Kraken notifications. If you’re among the 2,000 affected accounts, Kraken should have contacted you directly.
- Watch for targeted phishing. If your support data was viewed, attackers know you’re a Kraken customer. Expect convincing fake emails referencing real account details.
- Review your KYC documents. If you submitted a passport or ID to Kraken, consider monitoring for identity theft. Services like Identity Guard or LifeLock can flag if your personal data appears in new contexts.
- Use a dedicated email for crypto. If your primary email is tied to your exchange accounts, consider creating a separate, hardened email address (ProtonMail, Tutanota) used only for crypto.
- Never respond to “support” messages on social media. Legitimate exchanges won’t DM you on Twitter or Telegram asking you to verify your account.
The Bottom Line
Kraken handled this about as well as a company can: fast disclosure, refusal to pay, law enforcement cooperation. But the response isn’t the story.
The story is that criminal groups have built a functioning labor market for insider access. They’re recruiting employees at named companies, paying in crypto, and running operations sophisticated enough to hit the same target twice through different insiders.
Every crypto exchange, bank, and telecom company is a target. The question isn’t whether employees at these companies are being recruited: they are. The question is whether those companies are watching for it.
References
- CoinDesk: Crypto Exchange Kraken Targeted in Extortion Attempt (April 13, 2026)
- HackRead: Kraken Exchange Faces Extortion After Insider Recorded System Footage
- PYMNTS: Kraken Reports Criminal Extortion Attempt Involving Insider Recruitment
- Check Point Research: Cyber Criminals Are Recruiting Insiders in Banks, Telecoms, and Tech