Skip to main content
Suggest a service
Back to news Editorial

What Happens to Your ID After KYC: The 2026 Breach Record

KYC is not a check you pass — it is a copy of your passport, address and bank details held by the venue, its vendors and its vendors’ vendors, for at least five years after you leave. What 2026 actually put on the record: Ledger, Trezor, SafePal, Bits of Gold, Sumsub and Coinbase — what leaked, who was holding it, why wrench attacks rose 33%, and what still works afterwards.

19 min read NoKYCZone Editorial

Every other guide on this site answers how: how to buy Bitcoin, how to buy Monero, how to spend it and how to sell it, each without handing over a passport. This one answers the question underneath all four, and it is the one we get asked most: what actually happens to the identity documents when you do hand them over.

The short answer is that KYC is not a check you pass. It is a copy that gets made — of your passport, your face, your address, your bank details — then duplicated to processors you were never told about, retained by law for years after you close the account, and eventually disclosed. Sometimes by a breach. Sometimes by a bankruptcy court. Sometimes by a support contractor who was offered cash. 2026 is the year that stopped being an argument and became a record, and the record is what this article is.

KYC is not a check, it is a copy with a retention clock

The mental model most people carry is a door check: you show the ID, the bouncer looks, you go in. That is not what happens. The document is photographed, the selfie is stored, the address is filed, and the resulting record is kept.

It is kept because it has to be. Under the FATF recommendations, countries must require regulated institutions to retain customer due-diligence records for at least five years after the business relationship ends. The EU's Anti-Money Laundering Regulation writes the same figure into a single binding rule: Article 77 AMLR sets a uniform five-year retention period and then obliges the entity to delete the personal data when it expires — the regulation generally applying from 10 July 2027. Several member states already sit at the top of the permitted range instead: Spain and Luxembourg require ten years where France and the Netherlands apply five.

Read that from the user's side and two consequences fall out, both counter-intuitive.

First, closing your account does not start a deletion, it starts a clock. The five years run from the end of the relationship, not from the day you uploaded the document. Deleting the app changes nothing.

Second, the right to erasure does not apply to it. GDPR's Article 17 yields where processing is required to comply with a legal obligation, and AML record-keeping is exactly that. You can ask an exchange to delete your marketing profile. You cannot ask it to delete the KYC file, and it cannot comply if you do. That is not the exchange being obstructive — it is the design.

So the honest framing of every verification you have ever completed is this: a copy of your identity documents exists, in at least one database, for a minimum of five years after you last used the service, and you have no mechanism to withdraw it. Everything below is about who else ends up holding that copy.

The chain is much longer than the exchange

Here is the part that almost nobody models correctly. When you verify with an exchange, you are not trusting one company. You are trusting the identity-verification vendor it outsourced the check to, the ticketing platform its support team uses, the analytics tool its growth team plugged into the customer table, and the fulfilment or payment processor that handles your orders. Each of those is a separate company with a separate security posture, and you were never shown the list.

2026 supplied a run of evidence at exactly that layer. A public tracker of identity-verification provider incidents records several in close succession.

Sumsub, one of the largest identity-verification vendors serving crypto platforms, disclosed on 4 February 2026 an intrusion dating to July 2024 — detected only in January 2026, which is roughly eighteen months undetected. The entry point was a malicious attachment submitted through a third-party support-ticketing platform. The company states that identity documents and biometric data were not accessed, and that the exposure covers names plus a subset of emails and phone numbers. Take that at face value and the structural point still stands: the users affected had a relationship with an exchange, not with Sumsub, and had no way to know the vendor existed.

IDmerit was reported in November 2025 to have left an unsecured, password-less MongoDB instance exposing roughly one billion personal records across 26 countries — full names, addresses, postal codes, dates of birth, national identification numbers, phone numbers and emails. IDmerit disputes that the data was its own, and that dispute is unresolved; the record is included here as reported rather than as settled fact. Even discounted, a dataset of that shape is what an aggregated KYC industry produces as its failure mode.

AU10TIX had administrator credentials sitting exposed online for over a year — compromised December 2022, discovered June 2024 — covering identity documents, names, dates of birth, nationalities and identity numbers. Veriff reported unauthorised access around 18 November 2025, detected 10 December, exposing government ID images, postal addresses and dates of birth for roughly 8,583 customers of a single downstream client. Persona left dashboard source code on a public cloud bucket in February 2026 — not user data, but the verification logic itself.

The uncomfortable arithmetic is that the number of parties holding a copy of your document is not one. It is one plus however many vendors the first party used, plus however many they used. You consented to the first. You were not asked about the rest.

2026: the year the leaks were shipping databases

The crypto-specific incidents of 2026 share a feature that makes them worse than a password dump, and it took a while for the industry to say it plainly.

5 January 2026 — Ledger, via Global-e. Ledger confirmed that customer data was exposed through Global-e, the third-party merchant of record handling its international orders. Exposed: full names, shipping addresses, email addresses, phone numbers and order details. Not exposed: payment data, recovery phrases, private keys, PINs. Ledger's own systems were not breached — for the second time, the company was compromised through a partner rather than through its product.

16 August 2026 — three at once, two of them through the same bug. Reporting on the cluster sets out the detail:

  • Trezor, via fulfilment provider ShipMonk — 13,689 customers (11,742 with full exposure, 1,947 partial), names, emails, phone numbers and shipping addresses, covering shipments between 10 May and 8 August 2026. Root cause: CVE-2026-72898, a SQL-injection flaw in Metabase.
  • SafePal39,798 customers, names, emails, phone numbers, shipping addresses and purchase details, covering orders from 2 March 2025 to 11 April 2026. Root cause: an authorisation vulnerability in a third-party order-tracking plugin.
  • Bits of Gold, Israel's largest regulated crypto broker — roughly 200,000 customers, and the worst payload of the three: names, Israeli national ID numbers, emails, phone numbers, IP addresses, bank account details and public wallet addresses. Same CVE, same Metabase flaw, disclosed within days of detection. The company says no funds, private keys, passwords or scanned ID documents were exposed.
253,487 customers in a single day, across three companies, largely through one unpatched analytics tool. None of the three was breached at its core product. All three were breached through something bolted onto it.

Now put the payloads side by side. A leaked exchange password is a nuisance you fix by rotating it. A leaked shipping address attached to a hardware-wallet purchase is a permanent statement that a specific person at a specific street address owns self-custodied crypto. You cannot rotate your home. And a leaked wallet address attached to a legal name and a bank account — the Bits of Gold payload — collapses the separation between a public ledger and a private identity in one file.

May 2025 — Coinbase, and the insider route. Worth including because it is the clearest case of the failure mode that no amount of engineering prevents. Overseas customer-support contractors, offered cash, began copying data on 26 December 2024. It was caught on 11 May 2025 — the same day the extortion email arrived demanding 20 million dollars. Coinbase refused to pay and offered a matching 20-million-dollar bounty instead, which is the right call and does nothing for the people whose files were already copied. The breach notification filed with the Maine Attorney General puts the count at 69,461 individuals. The exposed set: names, addresses, phone numbers, email addresses, masked social security numbers, masked bank-account numbers, some bank account identifiers, account data, and images of government-issued IDs. Company estimates for remediation ran between 180 and 400 million dollars.

That last figure is the one to hold on to. Coinbase is a listed US company with a security budget larger than most of its competitors' revenue, and it sits in the same mandatory-KYC tier as the two baselines we index for comparison, Kraken and Binance. The variable was that the data existed in a support tool that a human being could be paid to open.

The threat model moved from your bank account to your front door

For a decade the standard answer to "so what if my KYC data leaks" was identity theft and phishing — annoying, insurable, survivable. In 2026 that answer stopped being adequate.

CertiK's H1 2026 wrench attack report — "wrench attack" being the trade term for extracting keys from a person by physical coercion rather than from a system by exploit — documents 52 verified incidents in the first half of 2026, against 39 in H1 2025, a 33 percent rise. Recorded financial exposure went from 10.5 million dollars to 124.1 million, close to a twelvefold increase.

The tactical breakdown is what makes it relevant to a data-breach article:

  • Home invasion rose from one incident in H1 2025 to twenty in H1 2026, roughly 41 percent of all cases.
  • Kidnapping rose from 12 to 16. Torture held at 4, murder at 1.
  • Europe accounted for 39 of the 52 incidents, and France alone for 33 — 63.5 percent of the global total.
Home invasion requires a home address. Twenty of them, in six months, in a category that had one the year before.

The link between leaked commerce data and physical risk is not new, and the template case is well documented. Ledger's July 2020 e-commerce breach exposed approximately 1 million email addresses and 272,000 records containing names, phone numbers and home addresses — a dataset still catalogued publicly. What followed was not credit-card fraud. It was extortion emails demanding 700 to 1,000 dollars in Bitcoin with explicit threats to the recipient's home, and in 2021, physically tampered "replacement" devices mailed to addresses from the dump, shrink-wrapped and accompanied by fake letterhead instructing the victim to enter their recovery phrase into modified hardware.

That is the mechanism, and 2026 refreshed the input data. A hardware-wallet shipping database is, by construction, a list of people who self-custody, filtered for the ones who cared enough to buy a device, with delivery addresses attached. There is no more efficient targeting list in this industry, and three of them leaked this year.

The proportionate reading matters here, and we will not inflate it: 52 incidents globally is a small number against tens of millions of holders, and the median reader's realistic exposure is extortion spam rather than a home invasion. But the trend line is the wrong direction, the concentration in one country is stark, and the input is precisely the data category that keeps leaking.

Bankruptcy publishes what no hacker had to steal

There is a disclosure route that involves no attacker at all, and almost nobody plans for it.

When Celsius filed its financial disclosure on 5 October 2022, the 14,500-page document entered the public court record carrying customer names alongside the types, amounts and dates of their transactions — covering, by press counts at the time, more than 600,000 users. Home addresses were redacted. Names were not. Celsius asked the court to seal them and the judge repeatedly refused, on the entirely ordinary grounds that creditor identities are public in bankruptcy.

The second-order effect is the one that should worry a crypto holder. A name published next to a dated transaction amount is a matching key. Anyone willing to do the work can line those dated amounts up against on-chain activity and attach a legal name to wallets that were never linked to one. A custodial platform's insolvency de-anonymised its users' chain history, permanently, through the front door, in a filing that was supposed to be routine.

No exploit. No ransom demand. No vendor at fault. Just a company that held identity data and then ran out of money — the single most common event in this industry's history.

What this argues, and what it does not

It does not argue that exchanges are negligent. Read the cases again: Coinbase refused the ransom and disclosed publicly. Bits of Gold and Trezor disclosed within days of detection. Ledger's own infrastructure was not breached in 2020 or in 2026, in both cases a partner's was. These are largely competent organisations with real security teams, and the data leaked anyway.

It does not argue that KYC has no purpose, and it does not argue that avoiding it exempts anyone from anything. Tax obligations are a separate legal regime that applies regardless — a point we make in the selling guide and repeat here.

What it argues is narrower and, we think, hard to dispute. The only variable a user controls is whether the record was created. Once it exists, its fate is out of your hands: it can be breached at the venue, breached at a vendor you never heard of, copied by a bribed contractor, published by a bankruptcy court, or simply retained for five to ten years while any of those things has time to happen. Data that was never collected has none of those failure modes. That is not a privacy slogan, it is the whole of the argument, and every incident above is an instance of it.

What "no data collected" actually looks like

This is where the abstraction becomes a list. Of the 28 services we index, 13 require no signup at all and 11 require an email address — and the difference between those two columns is precisely the difference between a company that can leak your identity and one that has nothing to leak.

The instructive part is the credential design, because several of these services solved a problem the mainstream treats as unsolvable: how do you run an account system with no identity in it?

ServPrivate, the highest-scored entry in the index at 9.7/10, issues a 16-character token at first payment and that token is the only credential for the life of the account — no name, no email, no phone, no password-reset address. The consequence is structural rather than promissory: there is no fallback identifier an operator could be compelled to produce, because none was ever created.

Mullvad at 9.4/10 does the same with a 16-digit account number and nothing else, and its no-logs claim belongs to the very short list that has been tested rather than asserted — a 2023 Swedish police raid produced no customer data to seize. IVPN at 9.3/10 is the near-twin from Gibraltar, with six consecutive annual Cure53 no-logs audits published in full; the head-to-head covers the differences.

SMSBurner at 9.6/10 goes further still: the server generates a 16-character seed phrase and the seed is the account — no email, no password, no username and no recovery flow, which is a real cost honestly priced. MoneroSMS at 6.9/10 is the Monero-primary alternative with an onion mirror. Both matter for the same reason: a phone number tied to your carrier line is the identifier that survives every other precaution you take, and it is the one that gets SIM-swapped.

GrabMail at 6.9/10 has no account at all — no email, no password, no payment, no cookie — and deletes every message after five days. It is candid about the trade: on a shared domain the address is the only secret, so it is excellent plumbing for a verification code and the wrong tool for anything you would mind a stranger reading. SimpleLogin at 7.5/10 is the opposite trade — it needs an account email, which is why it sits at discreet (L2) — but it is open-source at every layer, audited by Securitum in 2022, and it gives you one alias per venue.

And at the floor of the ladder, Bisq at 8.7/10 and BasicSwap at 9.1/10 are the only two trustless (L0) entries in the index — no company holds funds, no company holds an account, and there is consequently no customer table to breach, subpoena or sell in a liquidation. That is what the top of our KYC ladder is measuring, and this article is the reason the ladder is shaped the way it is: L0 has nothing to leak, L1 has a policy, L5 has a file.

One honest limit, because it is the exact limit the 2026 breaches exploited. No-signup is not no-trace when a physical object has to be delivered. Shipping a hardware wallet creates an address, and that address is what leaked at Ledger, Trezor and SafePal — not their KYC, which they mostly do not collect. Our spending guide covers the delivery problem in more detail; the short version is that the strongest no-KYC categories are the ones with nothing to ship.

What to do if you have already verified

Most readers have. The realistic question is not how to undo it — you cannot — but what still moves the needle afterwards.

  • Accept that the copy is permanent for now. The AML retention clock runs for five years past your last transaction, ten in some jurisdictions, and no deletion request overrides it. Plan around the file's existence rather than its removal.
  • Stop reusing one identifier across venues. A single email address across ten platforms means one leak is enough to correlate all ten. An alias per venue makes each leak attributable to its source and individually revocable — the cheapest structural improvement on this list.
  • Get your carrier number out of the loop. It is the identifier that anchors SIM-swap attacks and survives every other change; the SMS category exists for this.
  • Never ship anything crypto-related to your home if you have an alternative. This is the specific, evidenced lesson of 2026 rather than general advice. A parcel locker or a pickup point costs nothing and removes your address from the next order database that leaks.
  • Do not confirm holdings anywhere that pairs with an address. Support tickets, warranty registrations, giveaway forms and forum profiles are all places people volunteer the combination that a breach would otherwise have to assemble.
  • Do not consolidate a KYC-linked balance with a private one. A transaction that spends several inputs at once asserts that one entity controlled all of them, permanently and publicly — merging a verified history into an unverified stack is irreversible, and we cover it in the buying guide.
  • Treat extortion mail as commodity spam. Post-breach emails claiming specific knowledge of your holdings are overwhelmingly bulk-sent from a leaked list. Possession of your address is not possession of your keys.
  • Move the next one, not the last one. You cannot un-verify. You can make the next service you sign up for one that never asks — which, on the evidence above, is the only step that changes anything structurally.

Common questions

Can I make an exchange delete my KYC data?

Generally no, and not because the exchange is refusing. AML record-keeping is a legal obligation, and GDPR's right to erasure yields where processing is required to comply with one. Under Article 77 AMLR the retention period is five years from the end of the relationship, after which deletion becomes mandatory rather than optional — but during those years the request has no legal force. You can usually have marketing and analytics profiles deleted; the identity file is a different category.

Is my ID safe if the exchange itself is never hacked?

The 2026 record says that is the wrong question. Ledger, Trezor, SafePal and Bits of Gold were all compromised through third parties — a merchant of record, a fulfilment provider, an order-tracking plugin and an analytics tool. Coinbase was compromised through support contractors. In none of these cases was the company's core product breached. Your exposure is the union of every vendor in the chain, and you are not shown that list.

Which is riskier, the exchange or the identity-verification vendor?

The vendor is the higher-leverage target, because it aggregates. An exchange breach exposes that exchange's users; a verification vendor breach potentially touches every platform that outsourced checks to it. That is the structural concern raised by the Sumsub disclosure in February 2026, independent of how limited that particular exposure turns out to be, and it is what makes a reported billion-record identity dump plausible in a way a billion-user exchange never would be.

Does a KYC breach put my coins at risk?

Not directly — leaked identity data does not move funds, and none of the 2026 incidents exposed private keys or recovery phrases. The risk is indirect and it is real: targeted phishing that knows your real name and purchase history, SIM-swap attempts against a known phone number, tampered hardware mailed to a known address, and at the extreme end the physical coercion category that CertiK measured rising 33 percent year on year.

Why were hardware wallet buyers specifically targeted in 2026?

Because a hardware-wallet shipping database is the highest-quality targeting list in the industry. Every entry is a person who self-custodies, who cared enough to buy a dedicated device, with a verified delivery address attached. The irony is exact: the purchase that removes your coins from a custodian's risk is the purchase that puts your address in a merchant's database.

Is avoiding KYC only for people with something to hide?

The 52 people in CertiK's H1 2026 count were not hiding anything. They were identifiable, and someone knew where they lived. The case for minimising the record is the same case as for not publishing your bank balance: not concealment, but the ordinary judgement that data which is not collected cannot be leaked, subpoenaed, sold in a bankruptcy, or used to find you. Legal obligations — tax above all — are unaffected either way.

What is the single highest-value change I can make?

Stop shipping crypto hardware to your home address, and use a distinct email alias per service. Those two cost nothing, require no technical skill, and address the two data categories that actually leaked in 2026. Everything else on the list is a refinement.

Does using a VPN protect me from this?

It protects the IP address, which is a genuine gain — Bits of Gold's leak included IP addresses, and IVPN and Mullvad are in the index precisely because they collect nothing to leak in the first place. It does nothing about a document you already uploaded or an address you already gave a courier. Fix the collection; the VPN is hygiene layered on top.

Bottom line

The most useful thing this record shows is that the usual advice is aimed at the wrong layer. Choosing a reputable exchange, enabling hardware two-factor and using a strong password are all worth doing, and not one of them would have helped a single person in any incident above. Their data leaked through a fulfilment provider, an analytics tool, a bribed contractor and a bankruptcy filing.

Two things generalise past every service named here. The number of parties holding your identity documents is unknown to you, and it is never one — the vendor chain is invisible by construction, and it is where 2026's breaches actually happened. And retention means the exposure window outlives the relationship: the file survives the account by five years minimum, which is ample time for a company to be acquired, breached, or wound up.

Against that, the only durable control is upstream of all of it. A record that was never created cannot be leaked by a vendor you were never told about, cannot be copied by a contractor who was offered cash, and cannot be filed in a court docket by a company that has run out of money. That is the entire thesis of this site, and this year wrote the evidence for it.

This is editorial analysis, not legal, security or financial advice.

Browse the directory

See the no-KYC services we cover, scored and verified every six hours.

Open the index

More from the editorial