BlockInsider
  • NEWS
    • Bitcoin
    5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

    5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

    April 21, 2026

    BingX Q1 2026 Surge: AI User Base Tops 5M as TradFi Drives Half of Trading Volume

    April 21, 2026

    BingX Extends Chelsea FC Deal to Strengthen Global Sports Brand Presence

    April 16, 2026
    • Ethereum
    5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

    5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

    April 21, 2026

    BingX Q1 2026 Surge: AI User Base Tops 5M as TradFi Drives Half of Trading Volume

    April 21, 2026

    BingX Extends Chelsea FC Deal to Strengthen Global Sports Brand Presence

    April 16, 2026
    • Altcoins
    5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

    5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

    April 21, 2026

    BingX Q1 2026 Surge: AI User Base Tops 5M as TradFi Drives Half of Trading Volume

    April 21, 2026

    BingX Extends Chelsea FC Deal to Strengthen Global Sports Brand Presence

    April 16, 2026
    • Bitcoin
  • ANALYSIS
  • MARKET
    • Crypto prices
      • Bitcoin
    • Exchanges
  • LEARN
    • Crypto Glossary
$1000 WELCOME BONUS
No Result
View All Result
bitcoinBTC/USD
$ 68,840.8 1.84%
ethereumETH/USD
$ 2,146.5 2.65%
solanaSOL/USD
$ 85.2 3.58%
Market Cap:
$0.00
24h Volume:
$0.00
Dominance:
0.00%
BlockInsider
No Result
View All Result
Home Crypto

Unpacking Sumsub’s Latest Security Breach: What Happened and What It Means

An in-depth look at how a malicious support ticket attachment bypassed defenses for 18 months, exposing customer data on the KYC verification platform.

Robert Green by Robert Green
Feb 10, 2026
2 min. read
Unpacking Sumsub’s Latest Security Breach: What Happened and What It Means

Key Points

  • Sumsub disclosed a previously undetected security breach exposing limited customer contact data.
  • Delayed discovery raised concerns among crypto platforms relying on third-party KYC providers.

Sumsub reported on February 4 that a security breach had remained undetected for approximately 1.5 years.

The breach involved an external threat actor submitting a malicious attachment through a third-party customer support ticketing system.

Unpacking Sumsub’s Latest Security Breach: What Happened and What It Means Unpacking Sumsub’s Latest Security Breach: What Happened and What It Means Unpacking Sumsub’s Latest Security Breach: What Happened and What It Means

As a result, limited personal data linked to customer accounts was exposed, according to the company’s disclosure.

Sumsub provides KYC verification services for individuals and businesses, using AI tools to support fraud prevention and regulatory compliance globally.

The platform also supplies compliance-related services to blockchain analytics and risk-monitoring firms.

Its tools are widely used across the crypto industry by exchanges and service providers seeking to prevent fraud and money laundering.

Details of the security incident and industry response

Sumsub stated that the unauthorized activity occurred in July 2024 and was identified during a retrospective security review in January 2026.

The company reported that the malware enabled limited access only to a support-related internal environment.

Exposed information reportedly included names, email addresses, and phone numbers, while biometric data and financial details were not compromised.

Sumsub noted that its core production systems, APIs, and live ID verification workflows were not affected by the incident.

After identifying the issue, the firm initiated incident response procedures, engaged forensic cybersecurity experts, and notified affected customers.

Additional measures were introduced, including enhanced threat detection, stricter access controls, and expanded monitoring and testing programs.

The company also reiterated that it undergoes regular security audits and holds multiple international security certifications, as outlined in its official update.

The delayed disclosure drew public criticism, including comments from crypto investigator ZachXBT on social media platforms.

Some industry participants expressed concerns that the late detection could undermine trust in compliance service providers.

Sumsub responded that this was its first incident of this nature in a decade, while acknowledging a separate 2025 case involving Merkur AG that reportedly resulted in no data exposure.

Potential impacts on crypto firms remain under assessment, with limited public confirmations from affected platforms so far.

One Canadian crypto exchange stated publicly that only basic contact information may have been accessed and that its internal systems were not compromised.

The incident has renewed attention on the importance of vendor risk assessment when selecting third-party security and KYC providers in the crypto sector.

Read More Insights

5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

5 Warning Signs That Signal a Digital Finance Scam Every Investor Should Know

April 21, 2026
BingX Q1 2026 Surge: AI User Base Tops 5M as TradFi Drives Half of Trading Volume

BingX Q1 2026 Surge: AI User Base Tops 5M as TradFi Drives Half of Trading Volume

April 21, 2026
Please login to join discussion

News

  • Crypto
  • Bitcoin
  • Ethereum
  • AI
  • DeFi

Market

  • Top gainers
  • Cryptocurrencies
  • Exchanges
  • Converter

Learn

  • Glossary

Company

  • Contact
Telegram Instagram Youtube Tiktok Linkedin Medium Pinterest Tumblr

Disclaimer: By using this website, you agree to the Terms and Conditions.

BlockInsider has no affiliation or relationship with any coin, business, project, or event, unless otherwise specified.

None of the information you’ve read on BlockInsider.com should be taken as investment advice.

Buying and trading cryptocurrencies should be considered a high-risk activity.

Please do your own due diligence before making any investment decision.

BlockInsider is not responsible, directly or indirectly, for any damage or loss incurred, alleged or otherwise, in connection with the use or reliance on any content you have read on the site.

  • © 2014 - 2025 BlockInsider - All rights reserved.
No Result
View All Result
  • NEWS
    • Bitcoin
    • Ethereum
    • ETFs
    • Memecoins
  • ANALYSIS
  • MARKET
    • Crypto prices
    • Top Exchanges
    • Top Gainers Today
    • Crypto Converter
  • LEARN
    • Glossary

© 2014 - 2025 BlockInsider - Rights reserved.