# Sumsub, European KYC third party company, suffers a data leak

**URL:** https://discuss.privacyguides.net/t/sumsub-european-kyc-third-party-company-suffers-a-data-leak/35360
**Category:** News
**Tags:** article
**Created:** 2026-02-10T09:58:13Z
**Posts:** 3

## Post 1 by @PurpleDime — 2026-02-10T09:58:13Z

> **[The Sumsub Incident and the Future of Cloud Compliance - Fincrime Central](https://fincrimecentral.com/sumsub-incident-cloud-aml-risk-management/)**
>
> The Sumsub security incident demonstrates the inherent data breach risk when using third party cloud providers for identity verification and transaction monitoring services.

**TL;DR:**

> _**Sumsub identified a security incident in early 2026 involving unauthorized activity that originated from an external threat actor who submitted a malicious attachment through a third-party support ticketing platform in July 2024. […] While the company confirmed that identity document images and bank details remained secure, the exposed data included names, email addresses, and phone numbers for a specific subset of accounts.**_

> _The discovery of this intrusion occurred retrospectively during a routine security review, leading to immediate incident response and direct notification to all affected customers through their support manager_ **- FIN CRIME CENTRAL**

Sumsub is a “trusted third party” that verifies the identity of millions of internet users via banks, fintech, crypto, gambling…

Unfortunately, I can’t find any mainstream English news sources reporting on this issue. The only recognizable English source reporting on it is Sumsub’s own blog post, which, of course, is biased.

> **[Security Incident Update | Sumsub](https://sumsub.com/newsroom/security-incident-update/)**
>
> Security Incident Update

---

## Post 2 by @AnonymousPenguin — 2026-02-10T10:10:36Z

To cybersecurity experts:

Is there any way the set up of databases can be set up such that a leak cannot happen? Doesn’t it all depend on the cloud architecture, E2EE, mandatory 2FAs, etc.?

Is this really that hard to ensure?

---

## Post 3 by @FranklyFlawless — 2026-02-11T05:04:38Z

> [@AnonymousPenguin](#):
>
> Is there any way the set up of databases can be set up such that a leak cannot happen?

No.

> [@AnonymousPenguin](#):
>
> Doesn’t it all depend on the cloud architecture, E2EE, mandatory 2FAs, etc.?

No.

> [@AnonymousPenguin](#):
>
> Is this really that hard to ensure?

Yes.
