KYC / AML Disclosure
PII over-disclosure, KYC-anchored leaks, custody-chain regulatory violations.
Revolut: It kept handing over customer data for months, answering disclosure requests that arrived through Italy's state-certified email network (PEC; Italian prosecutors investigating)
the state certifies delivery, but nothing verifies the requester's authority before the data goes out
IDScan.net: More than 153 million scanned driver's licenses handed over at counters were being sold on the dark web
the check ends in a moment, the image does not
FCA fines Starling Bank £29m: since 2017, the automated sanctions screening had been matching customers against only a fraction of the list
the screening ran
Paysafe fake SDKs: 17 packages posing as legitimate payment SDKs exfiltrated developers' secrets, payment API keys and all
The supply-chain security firm Socket detected 17 malicious packages (13 on npm, 4 on PyPI) that pose as SDKs for the payment services Paysa…
A7A5: a ruble-backed stablecoin moved $110B under sanctions
fully traceable on-chain, yet nothing proves or blocks a sender's sanctions status at transaction time (CertiK / Elliptic)
Sumsub: An 18-Month Undetected Intrusion Into a Support Environment Exposed Customers' Names and Contact Details
Sumsub, a global identity-verification (KYC) vendor, disclosed unauthorized access to an internal support-related environment. In July 2024,…
IDMerit: the disputed billion-record KYC exposure
an unsecured database was found, but no one can prove whose data it was (Cybernews report, IDMerit denial)
Wirecard: forged bank balance confirmations asserted €1.9B that didn't exist
a financial attribute disclosed without independent verification
The Coinbase KYC Insider Breach
When Regulation-Mandated Storage of Raw PII Becomes the Breach Surface