Summary
Haruko, a cryptocurrency infrastructure and technology services provider serving institutional and professional clients, has confirmed that it suffered a cyberattack that affected 15 of its client organizations. Haruko provides trading infrastructure, data services, and operational tooling to cryptocurrency market participants. The company has disclosed the incident publicly but has not detailed the attack vector, the categories of data accessed, or the scope of exposure within the 15 affected client organizations. Haruko stated it has notified affected clients and is conducting an investigation with third-party cybersecurity assistance.
Timeline
| Date | Event |
|---|---|
| September 2026 | Cyberattack against Haruko infrastructure; 15 client organizations affected |
| Sep 18-19, 2026 | Haruko publicly confirms the attack; notifies affected clients; investigation underway with third-party cybersecurity assistance |
What Happened
Haruko operates as a technology layer for cryptocurrency market participants, providing infrastructure that connects clients to exchanges, data feeds, and operational workflows. A breach of a shared infrastructure provider creates downstream exposure across all clients who depend on that infrastructure — the 15 affected organizations represent client relationships rather than a count of individual end users. The actual exposure surface depends on what data Haruko held on behalf of each client and what access the attacker obtained to client-specific configurations, API credentials, trading data, or operational records.
Cryptocurrency infrastructure providers may hold exchange API keys, trading history, portfolio data, compliance records, and identity documents for their clients. Haruko has not disclosed whether any of these categories were accessed. Affected organizations should review all credentials, API keys, and access tokens associated with their Haruko integration and rotate any that may have been exposed, regardless of whether Haruko confirms those specific items were accessed.
Domain Intelligence
haruko.com — 60.95
haruko.com scores in the low-trust range at 60.95, carrying only a T6_V2_CANONICAL flag and no T5 flags. The absence of T5 flags means the topology layer found no threat intelligence observations associated with haruko.com prior to this incident. Haruko is the breached infrastructure provider.
The Trust Observatory · thetrustobservatory.com · September 19, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026