Timeline
- 7.5
Kraken Refuses To Pay Extortion Demand Over Stolen Client Data
Kraken disclosed that stolen client data was used in an extortion attempt against the exchange, and publicly stated that it refused to pay the attackers' demand. The disclosure concerns client data rather than a loss of customer funds or exchange reserves. The incident is a security and trust event for Kraken's users, whose data is at the center of the extortion attempt, and the exchange's public refusal puts its position on record rather than resolving the matter privately.
- 7.5
Kraken Refuses to Pay Extortion Demand Over Stolen Client Data
Kraken has publicly refused to pay an extortion demand after client data was stolen, declining to meet the attackers' terms. The incident was described as an insider attack, meaning the data was taken by someone with legitimate internal access rather than through a purely external breach. A major exchange refusing to pay sets a public precedent for how crypto firms respond to data-extortion campaigns, and it pushes the industry's focus toward insider risk, user privacy and the security practices exchanges advertise. It also raises the stakes for Kraken's customers and regulators, because leaked identity data can enable phishing, account-takeover attempts, and physical targeting of crypto holders. The case highlights that perimeter defenses, encryption and multi-factor authentication address external attackers but do nothing against an employee who already holds valid credentials, which is why insider access controls and monitoring are the relevant mitigation. Kraken is legally named Payward, Inc., was founded in 2011, and by 2025 reported about $207 billion in quarterly trading volume as one of the world's largest exchanges.