BasedApp, the Singapore-based fintech that combines a crypto wallet, trading platform and Visa card, confirmed on Thursday that an unauthorized party gained access to an internal dashboard used to manage its Visa card program, potentially exposing KYC data belonging to some of its cardholders.

According to the company, the breach was first detected on 5 October 2026. "On 5 October 2026, we were alerted that an unauthorised party has gained access to an internal dashboard used to manage the Based Visa Card program. The attack was swiftly stopped and contained as soon as it was discovered," Based said in its public statement.

The data potentially accessed includes names, passport or ID numbers, dates of birth and addresses submitted as part of Based's identity verification process. The company said card numbers, CVV codes, PINs, ID photos and liveness check images were not exposed, nor were any funds held in the Based Wallet.

Based did not disclose how many cardholders were affected, describing the scope only as "certain" users of the Visa card program. Those affected received a notification email on Thursday. The company was direct about the implications for those customers: "If you are one of the affected users, consider that this data is compromised."

Based said it has informed the relevant authorities of the incident and that Visa card payments continue to function normally despite the breach. The company also used the announcement to warn customers about potential follow-up scams, stating that support is only available through its in-app chat and that no team member will contact users via private message on Telegram or X. Based said it had intentionally disabled comments on its public post about the breach for security reasons.

A pattern of large-scale data exposure

The Based incident adds to a string of recent data exposure events. Denmark's CPR registry, the national identification system, recently had 8 million national identifiers exposed. The week before, a cyberattack on Oracle exposed health data belonging to nearly 20 million people.

The breach also comes against a backdrop of heavy losses across the crypto sector more broadly. An estimated 1.26 billion dollars was stolen from crypto protocols in the third quarter, underscoring the scale of security challenges facing platforms that combine digital asset services with traditional payment infrastructure such as Visa-branded cards.

For European users of Based's Visa card, the exposure of passport and identity data raises the risk of identity theft and targeted phishing, even though the company maintains that no card numbers, PINs or wallet funds were compromised. Based has not said whether it will offer any compensation or additional protection measures to affected customers beyond the notification already sent.