{"id":99249,"date":"2024-11-09T16:25:14","date_gmt":"2024-11-09T20:25:14","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=99249"},"modified":"2024-11-09T16:25:21","modified_gmt":"2024-11-09T20:25:21","slug":"scammer-wears-mask-to-hijack-kraken-account","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/scammer-wears-mask-to-hijack-kraken-account\/","title":{"rendered":"Scammer Wears Victim&#8217;s Rubber Mask to Hijack Kraken Account"},"content":{"rendered":"\n<p>Kraken thwarted a scammer's attempt to hijack a Kraken account by spotting a Halloween-style mask during a video verification call. The scammer's inability to answer key <a href=\"https:\/\/coinscreed.com\/staging\/coinbase-clo-questions-sec-crypto-asset-claims.html\" data-type=\"post\" data-id=\"93903\" target=\"_blank\" rel=\"noreferrer noopener\">security questions<\/a> raised initial red flags, prompting the additional verification step.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-1024x576.jpeg\" alt=\"Scammer Wears Victim's Rubber Mask to Hijack Kraken Account\" class=\"wp-image-99255\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-1024x576.jpeg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-300x169.jpeg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-768x432.jpeg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-1536x864.jpeg 1536w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-2048x1152.jpeg 2048w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-860x484.jpeg 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1-1320x743.jpeg 1320w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Scammer Wears Victim's Rubber Mask to Hijack Kraken Account<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Scammer Attempt on Kraken Account<\/h2>\n\n\n\n<p>In order to reestablish access to your Kraken account, you may be requested to participate in a video call with a support agent to verify your identity.<\/p>\n\n\n\n<p>The centralized exchange reported that last month, an individual was observed donning a rubber mask reminiscent of Halloween in an attempt to deceive the worker on the other end of the call. However, the ruse was unsuccessful.<\/p>\n\n\n\n<p>During the initial round of reviews, the attacker had raised numerous red flags, including the failure to identify the assets that the account held. The agent who was working the case was compelled to request a video call in order to grant access to the account as a result of these flags. The Kraken staffer inquired further and verified the individual's identification during the conversation.<\/p>\n\n\n\n<p>\u201cOur agent was like: This is absolutely ridiculous. This is a rubber mask the guy's wearing,\u201d Kraken Chief Security Officer&nbsp;<a href=\"https:\/\/x.com\/c7five\/status\/1846147268044378127\" target=\"_blank\" rel=\"noreferrer noopener\">Nick Percoco<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>&nbsp;told&nbsp;<em>Decrypt<\/em>.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>There are deepfakes and then there\u2019s this guy. He\u2019s trying to gain access to a&nbsp;<a href=\"https:\/\/twitter.com\/krakenfx?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@krakenfx<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>&nbsp;client\u2019s account. Nice try, buddy!&nbsp;<a href=\"https:\/\/t.co\/gFD9LUM2D4\" target=\"_blank\">pic.twitter.com\/gFD9LUM2D4<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>\n\n\n\n<p>\u2014 Nick Percoco (@c7five)&nbsp;<a href=\"https:\/\/twitter.com\/c7five\/status\/1846147268044378127?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 15, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>\n<\/blockquote>\n\n\n\n<p>Percoco stated that the mask did not even resemble the individual the attacker was professing to be. Percoco perceived that the assailant had merely acquired a mask that vaguely matched the victim's description, as the victim was a Caucasian male in his early 50s.<\/p>\n\n\n\n<p>Additionally, this is not the initial instance in which an individual has donned a disguise in an effort to deceive Kraken.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201c[We] see things, from time to time, where people put on a fake mustache,\u201d he told&nbsp;<em>Decrypt<\/em>. \u201cThey show [ID] and it looks close because they wear the same style glasses, have a mustache, and have blonde hair. We see that from time to time. They never pass.\u201d&nbsp;<\/p>\n\n\n\n<p>\u201cBut this is the first time,\u201d he added, \u201cthat someone has gone out to the costume store to get a mask.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>To exacerbate the situation, the assailant lacked a credible identification card. Percoco clarified that the image was &#8220;clearly&#8221; Photoshopped and printed onto card stock, albeit with the appropriate information.<\/p>\n\n\n\n<p>Even though this was not a sophisticated attack, it underscores the potential for even sloppy fraudsters to access the <a href=\"https:\/\/coinscreed.com\/staging\/twitter-hacker-put-200m-users-private-information-up-for-grabs.html\" target=\"_blank\" data-type=\"post\" data-id=\"43439\" rel=\"noreferrer noopener\">private information<\/a> of everyday individuals. Percoco is of the opinion that attackers could achieve success despite their unpolished endeavor.<\/p>\n\n\n\n<p>I think it must [work],&#8221; he told&nbsp;<em>Decrypt<\/em>. &#8220;I think people wearing disguises, people who breach another place and get a copy of your government ID, and then print it out on glossy paper, holding that up\u2026 for some exchanges, that probably works.&#8221;<\/p>\n\n\n\n<p>He asserted that certain exchanges lack the same level of attention to detail that Kraken expects from its team. Companies that outsource their support are explicitly identified by Percoco as being more susceptible to errors.<\/p>\n\n\n\n<p>This implies that individuals who utilize <a href=\"https:\/\/www.investopedia.com\/tech\/what-are-centralized-cryptocurrency-exchanges\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">centralized exchanges<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> should not always depend on the company to protect them from malicious actors, if his assertion is accurate. According to Percoco, in order to safeguard themselves, users should implement two-factor authentication &#8220;everywhere&#8221;\u2014from their email to far beyond\u2014to prevent malicious actors from obtaining any personal information at any cost.<\/p>\n\n\n\n<p>Despite employing these safeguards, it is still possible for a user to fall victim to phishing schemes. He suggests the use of FIDO2 and passkeys, which are hardware keys that can transform your phone or laptop into your account password, for the highest level of security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kraken thwarted a scammer&#8217;s attempt to hijack a Kraken account by spotting a Halloween-style mask during a video verification call. The scammer&#8217;s inability to answer key security questions raised initial red flags, prompting the additional verification step. Scammer Attempt on Kraken Account In order to reestablish access to your Kraken account, you may be requested [&hellip;]<\/p>\n","protected":false},"author":36,"featured_media":99255,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[22746,22745,22744,21838],"class_list":["post-99249","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-hijack","tag-kraken-account","tag-scammer","tag-victim"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/Person-holding-mobile-phone-with-logo-of-American-crypto-company-Payward-Inc.-Kraken-on-screen-in-front-of-web-page-scaled-1.jpeg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/99249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/36"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=99249"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/99249\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/99255"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=99249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=99249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=99249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}