Crypto & Ransomware Brief — April 17, 2026
Cryptocurrency exchange Kraken disclosed it is facing extortion demands following two insider-related security incidents that compromised support system access. Attackers claim to possess internal system videos and are leveraging the breach for financial gain. Separately, Solana-based DeFi platform Drift Protocol announced plans to relaunch after securing $150 million in funding from a Tether-led consortium, following its record-breaking $285 million exploit on April 1st. The funding marks a rare recovery path for a platform hit by one of 2026's largest DeFi breaches.
On the ransomware front, Tennessee's Cookeville Regional Medical Center is notifying over 337,000 patients of a Rhysida ransomware attack that occurred in July 2025, exposing sensitive healthcare data in a delayed disclosure. Automotive data provider Autovista confirmed a ransomware infection disrupting operations across European and Australian systems. Meanwhile, threat intelligence reveals escalating sophistication: Sophos documented attackers abusing QEMU virtualization to hide operations and deploy PayoutsKing ransomware, while Microsoft flagged exploitation of four legacy vulnerabilities—including one patched 14 years ago—by ransomware operators including Storm-1175 deploying Medusa. In an unusual development, ransomware gang 0APT publicly threatened rival group Krybit with doxxing in an extortion dispute between criminal operations.
Sources: Bleeping Computer · Bloomberg · Crowdfund Insider · Infosecurity Magazine · SC World · Sophos · The Register