Spatiotemporal rift. Identity verification specialist Sumsub revealed this Wednesday, February 4 that it had been the victim of a security incident resulting in the exposure of personal data. Although the intrusion dates back to the summer of 2024, it was only recently discovered during a routine audit, highlighting the persistent challenges of retrospective detection in tech.
The key points of this article:Sumsub revealed a security incident that exposed personal data, discovered in January 2026 although the intrusion took place in July 2024.
The attack leveraged a third-party support ticket management platform, but high-risk data was not compromised.
An intrusion at Sumsub via technical support in July 2024
The investigation carried out by Sumsub indicates that in July 2024an external malicious actor exploited a platform third party support ticket management. By submitting a trapped attachment, the pirate managed to gain limited access to an environment internal dedicated to customer service. According to figures and details provided by the company:
Data exposed: Mostly names, plus a subset of email addresses and phone numbers.
Data preserved: High-risk information, such as biometrics, ID document photos, banking details or live verification systems, has not been compromised.
Scope: The incident was contained to the support environment and did not affect core production systems or client APIs.
Sumsub teams continue to work with ever more efficient AI solutions – Source: Compte
Late detection in January 2026
The most important point delicate of this announcement resides in the calendar. The activity unauthorized was only identified in January 2026a year and a half after the fact, during an in-depth security review. Sumsub immediately activated its response protocols incidentshired independent experts and began directly notifying impacted customers. To prevent any recidivismthe firm has already strengthened its controls access for technical staff and improved their capacity to surveillance. This incident occurs while Sumsub had just published its annual report highlighting an increase in 180% of sophisticated fraud in 2025, reminding us that even the guardians of digital identity are not immune to the flaws of their own subcontractors. The incident at Sumsub illustrates the growing vulnerability of software supply chains (third-party support platforms). Although the leak was limited to contact data, the 18-month detection time frame raises questions about the responsiveness of audit systems to silent attacks. For Sumsub, the challenge now is to restore confidence as the platform prepares to launch new AI-based verification tools in 2026.