A digital banking platform disclosed a data breach incident that involved the disclosure of sensitive customer information after a fraudulent government request was accepted as legitimate. The breach centers on the handling of a government-level request that was not genuine but was treated as authentic by the firm during a verification process. As a result, a subset of customers was exposed to the release of highly sensitive personal data tied to their accounts and transactions.

The information disclosed in the wake of the incident includes passport details, verification selfies, and transaction-related histories tied to Bitcoin activity. In addition to travel and identity documents, home addresses associated with affected accounts were also handed over as part of the response to the fraudulent request. The exposure underscores the potential risk to customers who rely on digital banks for identity verification and the handling of cryptocurrency-related activity within their accounts.

According to the firm, the handling of the fraudulent request did not result in any loss of customer funds. The statement indicates that while balance safety was preserved, the compromised data present a significant privacy and security concern for those affected. The disclosure also highlights the broader risk landscape facing digital financial service providers as they navigate the integration of digital identity elements, anti-money laundering safeguards, and crypto-related transaction records.

The incident has prompted scrutiny over internal verification controls and the processes used to validate government or third-party data requests. While the exact scope of affected customers has not been specified, the firm indicated that a subset of clients received notification about the data exposure and the kinds of data that were disclosed. The disclosure process appears to be part of an ongoing review of procedures and an assessment of what went wrong in validating a request that should have been thoroughly vetted before sensitive records were released.

Market observers note that the episode raises questions about how digital banks reconcile rapid customer verification with the need to prevent data breaches involving personal identifiers and cryptocurrency-related activity. The case also serves as a reminder of the heightened privacy implications when government-level requests intersect with consumer financial data, particularly in platforms that combine traditional banking features with digital asset activity. Regulators and industry commentators alike will be watching for further details about the incident, including any corrective measures, policy changes, and risk controls designed to prevent similar occurrences in the future.