The fallout from the collapse of FTX continues to create ripple effects across the crypto industry, and this time the spotlight is on Kroll, the financial advisory firm tasked with overseeing creditor claims. A new class-action lawsuit has been filed against Kroll, alleging negligence after a major data breach in August 2023 exposed sensitive information of thousands of creditors linked to FTX, BlockFi, and Genesis.
For creditors already facing years of uncertainty and drawn-out reimbursement processes, the breach has become another layer of frustration, as phishing scams tied to the leaked data have flooded their inboxes. With phishing emails reportedly arriving daily, many affected customers argue that Kroll failed to protect their personal information, compromising not only their claims but also their financial security.
The roots of the Kroll lawsuit
The lawsuit was filed in a U.S. district court by Hall Attorneys on behalf of FTX creditor Jacob Repko and others who claim they have been systematically targeted by cybercriminals since the breach. According to the complaint, hackers gained access to personal information after Kroll’s systems were compromised in August 2023. The stolen data has since been weaponized by malicious actors to orchestrate phishing campaigns against already vulnerable FTX creditors.
Plaintiffs argue that Kroll relied too heavily on email-only outreach to manage the claims process, leaving creditors exposed to identity theft and fraud. By centralizing communication without sufficient safeguards, Kroll inadvertently created a single point of failure that hackers exploited with devastating efficiency.
Daily phishing attacks and customer frustration
Among the most concerning outcomes of the breach is the relentless wave of phishing attempts. Victims, including prominent creditors such as Sunil Kavuri, have reported receiving scam emails almost daily, often personalized with their names. Screenshots shared on social media highlight the frequency and sophistication of these attempts, which mimic legitimate communication and attempt to extract sensitive login details or financial information.
For creditors who have already endured financial loss from the FTX collapse, these attacks add insult to injury. Instead of focusing on recovering their funds, many are now forced to navigate a minefield of fraudulent emails, unsure which communications are genuine. This not only delays the claims verification process but also increases the risk of additional financial damage.
Kroll’s history of security issues
The August 2023 breach was not the first time Kroll faced cybersecurity challenges. Earlier in 2024, the firm reportedly suffered another breach in which sensitive information related to client invoicing, accounts payable, and email addresses was stolen. This track record has amplified criticism against Kroll, with creditors questioning why the firm was entrusted with sensitive data in the first place.
Critics argue that repeated breaches highlight systemic weaknesses in Kroll’s security protocols. If the firm was aware of vulnerabilities but failed to act, the case for negligence becomes stronger. This lawsuit could force not only financial compensation but also operational changes in how Kroll manages digital security for bankruptcy proceedings.
Legal implications and potential compensation
The class-action suit seeks damages for the harm caused by the breach and aims to address systemic issues in Kroll’s approach to creditor communication. Nicholas Hall, a lawyer involved in the case, has indicated that eligible participants may receive monetary compensation depending on the court’s ruling.
If successful, the lawsuit could also set a precedent for how advisory firms are held accountable in managing sensitive data tied to high-profile bankruptcies. For crypto investors, who often find themselves caught between regulatory ambiguity and institutional oversight failures, such outcomes could improve data protection standards across the industry.
The broader context: FTX reimbursements
While creditors pursue justice through the courts, FTX’s bankruptcy process continues. The third round of reimbursements is scheduled to begin on September 30, with $1.9 billion set to be distributed. However, the payouts are expected to exclude foreign creditors from countries such as China and Russia due to regulatory restrictions.
This follows a second round of reimbursements in May that distributed over $5 billion, and an earlier February plan that promised $1.2 billion for small claimants with balances under $50,000. While progress is being made, many creditors remain dissatisfied with the pace and fairness of the process. The ongoing Kroll controversy only deepens their mistrust in the institutions managing recovery efforts.
Why this case matters for crypto regulation
The Kroll lawsuit underscores a broader issue: the fragility of data protection in the cryptocurrency industry. As exchanges collapse and bankruptcy proceedings expose sensitive information, creditors often become the weakest link. Without robust safeguards, personal data can easily be weaponized by criminals, compounding the financial losses investors already face.
This situation highlights the urgent need for stronger cybersecurity frameworks in the digital asset sector. Regulatory bodies in the U.S. and abroad have intensified scrutiny over exchanges and custodians, but less attention has been paid to the third-party firms responsible for managing claims and settlements. The Kroll case may shift this focus, drawing attention to the role such intermediaries play in protecting—or failing to protect—crypto users.
Lessons from the Kroll breach
The lawsuit against Kroll is more than a dispute over negligence—it is a test case for how accountability will be enforced in an industry riddled with failures. For FTX creditors, the breach represents another betrayal in a saga already marked by distrust, delays, and disappointment.
Whether or not the plaintiffs secure financial compensation, the case serves as a stark reminder that protecting customer data is as important as protecting their assets. In the fast-evolving crypto landscape, breaches and scams will remain a constant threat unless stronger safeguards are implemented. For Hedera, Ethereum, Bitcoin, and beyond, the lesson is clear: investor trust cannot exist without robust data security.
If the courts rule in favor of the creditors, it could lead to operational reforms at Kroll and similar firms, potentially reshaping the way bankruptcy claims are managed in future crypto collapses. For now, the case highlights just how intertwined cybersecurity, regulation, and financial recovery have become in the ongoing story of FTX.
Start Free Today. Unlock Your 15% Member Discount.
Access the Free Start program immediately and receive an exclusive 15% discount for your first Learning Path purchase.
Build your foundation before making your next investment decision.


