Financial privacy: how KYC and AML work in Revolut and Binance

How a system designed to keep us safe has turned financial data into one of our most dangerous assets
The modern financial system wants to know a lot about us. To open an account or use a major cryptocurrency exchange, we provide passport information, residential address, tax information, and sometimes confirm the source of income and the origin of funds. And that’s okay. Banks and financial companies are required to comply with KYC and AML requirements, fight fraud, and understand who they are dealing with. But here a simple rule arises: the more information a company requires from a client, the higher its responsibility should be for the protection of this data. If a client is obliged to prove to the bank who he is and where he got his money from, it is logical to expect that the person or service that one day comes for this information will be checked by the bank at least no less carefully.
As a result of many years of development of KYC and AML, a huge infrastructure has been created in which a person’s identity, his money and the history of his financial behavior are connected in one place. And two recent stories – with Revolut and Binance – show very well how this could end.
Two cases. Two completely different threats. And one common question: who really owns our financial data after we have given it to the financial system?
Revolut: Data collected for security purposes went to the wrong place
In September 2026 Revolut has confirmed the disclosureof sensitive customer information to an unauthorized third party. The reason was a particularly revealing type of attack: the attackers sent fake government requests, and the messages came from a real government department domain. Revolut perceived the requests as legitimate and passed on the information.
What is especially outrageous about this story is not the fact that the customer data ended up in the hands of strangers. Another thing is much more important: judging by the published information, they were not stolen as a result of a complex hack of the Revolut infrastructure (and leaks have occurred before – from banks, insurance companies, social networks, government agencies). They just came for them. They introduced themselves as a government agency. Sent a request. And Revolut handed over customer information. That is, the company to which a person entrusts his money, documents, address, transaction history and other sensitive information turned out to be ready to disclose this array of information to a third party without properly making sure that it really is who it claims to be.
But here an even more unpleasant question arises. Let’s assume for a second that the request actually came from a real government agency. And what? The very fact that someone is a representative of the state does not give him an unconditional right to obtain the client’s passport, his KYC dossier and the history of financial transactions. There must be a legal basis for such a request. The body must have appropriate powers. The request must relate to a specific person and specific matter, and the amount of information transmitted must be consistent with the legitimate purpose of the request.
And then a second question inevitably arises, to which there is no public answer yet: How thoroughly did Revolut check the legal basis of the data request itself?
Because if a request that looked official was enough to disclose sensitive financial information, the problem is much more serious than ordinary phishing. The result is an amazing asymmetry. When Revolut wants to obtain information from a client, the client must prove who they are, where they live, where they got the money from and sometimes why they are making a particular transaction. But when someone wanted to get information about the client himself, the verification system turned out to be such that it was able to be deceived by a fraudster who controlled an unauthorized address in the official domain of a government agency.
Revolut teaches its clients not to trust calls, letters and people introducing themselves as employees of banks or government agencies. Perhaps he should have taken his own advice this time. The Revolut story shows a scenario in which the system failed.
But the Binance story is more interesting. Because the system there, judging by the published materials, did not necessarily fail. It could have worked exactly as it was intended.
Binance: when a leak is not needed at all
In August 2026 Reuters reportedthat Binance handed over client data of Yuri Belenky to Russian authorities. According to the agency, information about cryptocurrency donations to Ukrainian fees was subsequently used in the criminal case against him.
Binance, for its part, states that responds to lawful requests from law enforcement agencies in accordance with applicable legal procedures. And this is where a much more difficult conversation begins.
Financial companies do need to cooperate with law enforcement. It is difficult to imagine a modern financial system in which a bank fundamentally refuses to provide information upon a proper legal request in the investigation of a serious crime. But there is a problem that cannot be solved with one phrase: “we comply with the requirements of the law.” Laws vary from state to state. What one jurisdiction considers legitimate political activity, donation, or support for a particular organization, another may consider a serious crime.
But the Binance story raises an even more unpleasant question. In 2023, Binance officially announced its complete withdrawal from Russia. The company sold its Russian business and directly stated that further work in the country is incompatible with its compliance strategy. Two years later, according to Reuters, Binance handed over its client’s data to Russian law enforcement agencies, which were then used for criminal prosecution.
And here I would like to ask a very simple question: why do Russian authorities continue to receive customer data from a company that has officially left Russia?
If Binance no longer does business there, on what basis should a Russian government agency be able to request information from it? And why does Binance consider itself obligated to fulfill such a request?
A formal answer “we cooperate with law enforcement agencies” is not enough here.
Leaving the market should mean not only the absence of an application in the Russian App Store, ruble trading pairs or a local office. The question is much deeper: Is when a company leaves a country, does that country’s power over its customers’ data end?
The Binance story shows that the answer may not be pleasant.
Which is worse: a leak or no need for a leak?
Imagine two doors to the same archive. Attackers can get through the first one if they deceive the security system. Government bodies will go through the second if they present documents that the platform recognizes as a sufficient legal basis. You can improve the first door endlessly: multi-factor verification of requests, independent confirmation, cryptographic authentication, internal employee control. And the improvement works successfully. But the second door exists intentionally. And this fundamentally changes the conversation about financial privacy.
The question is no longer whether Revolut protected a particular database well or poorly or whether Binance processed a particular request correctly or incorrectly. These are important questions, but they are secondary. The big question is this: Should there even be a system in which one private company decides to hand over a person’s detailed financial biography, access to which could radically change his life?
Cryptocurrency was supposed to solve the problem of the middleman
Bitcoin began as a system in which two people could transfer value to each other without a bank between them. But the mass user of cryptocurrencies today often comes not through self-storage of keys, but through a centralized exchange. And here a paradox arises. blockchain is public. The address itself does not necessarily tell the world who it belongs to. But once that address is securely linked to a specific person’s KYC profile, the blockchain’s public history can transform from a collection of anonymized transactions into a detailed financial map. A centralized exchange becomes a bridge between two worlds: a real person and a pseudonymous blockchain history. Therefore, KYC in cryptocurrencies sometimes gives the financial system even more analysis capabilities than a traditional bank account. The bank sees transactions within the banking infrastructure. blockchain is capable of storing the history of asset movements for years, and sometimes almost forever. If one of the points in this story is associated with a real person, past transactions may take on new meaning in retrospect.
“I have nothing to hide”
The conversation about financial privacy is often answered with a simple phrase: if you’re not doing anything illegal, why should you be afraid? But privacy never meant having to hide something. Most people don’t close the bathroom door because they’re committing a crime. We don’t publish emails with your spouse, search history, or bank statements on the town square—even though almost everything in them is perfectly legal. Privacy is not a criminal’s right to hide. This is the right of an ordinary person to independently determine who knows about him and how much. Financial data is especially sensitive because money reveals a surprising amount about a person. Where does he live? Where it happens. Who does business with? What does he buy? What organizations does he donate to? Which countries does he travel to? What services does he use? How much does he earn? How much have you saved? Payment history gradually turns into life history, which directly affects security.
The problem is not just Revolut and not just Binance
It would be too easy to end this article with the conclusion “Revolut does not protect data well” or “Binance transfers information to governments.” This is not a problem between the two companies. They are part of a system whose rules require customer identification, transaction analysis, storage of certain information and interaction with government agencies. You can replace Revolut with another bank. Binance is another exchange. The fundamental design will hardly change.
Both of these stories happened for the same reason: it is much easier for a financial company to cooperate with government agencies than to protect the interests of its client from them. Revolut was willing to hand over sensitive information following a request that it could not even properly verify. And Binance, according to Reuters, provided data to Russian authorities years after officially leaving Russia.
For the company itself, this logic is quite rational. Refusing a government agency means potentially getting into trouble. You will have to involve lawyers, check the reasons for the request, argue about its legality and the amount of information required. In the worst case scenario, you might conflict with regulators, receive fines, or create risks for your licenses. Transferring data is much easier. And here a fundamental conflict of interest arises. A mistake in favor of the client can be costly for the company. A mistake in favor of the state most often costs the client dearly. Therefore, the safest scenario for the company is not to ask unnecessary questions and cooperate. The faster a request turns into a standard compliance procedure, the lower the risks for the business itself. The financial company at this point is not its client’s lawyer. She is not obliged to look for reasons why the state should not give your data. Her own interest is much more prosaic: fulfill the requirements, close the request and not get into trouble.
That is why it is not enough to ask how reliable a bank, broker or cryptocurrency exchange is. It is important to understandin what jurisdiction the company is located and in front of which legal system it is really afraid to say “no”.
The price of convenience
The information that the system collects to protect a person can one day be used against him – by a criminal, the state, or simply an erroneous algorithm. And then the main financial asset of the 21st century will not be money or even Bitcoin. They will have information about who this money belongs to, where it came from, where it moved and what its owner did all his life. And whoever controls this information gains power that the financial system of the past simply could not provide.
This is why the expression “financial-digital concentration camp” in this article is not a statement that we already live in a totalitarian system, nor is it an attempt to make a literal historical comparison. It’s a deliberately harsh metaphor for where we’re headed: a world in which financial freedom increasingly depends not just on whether you own your money, but also on who controls the infrastructure for accessing it and information about you.
That’s why ParadTrade pays special attention to the choice of jurisdiction in which the company operates. For us, this is not a formality and not just a matter of the cost of a license or the convenience of doing business. ParadTrade lawyers evaluate jurisdictions primarily from the point of view of the client’s interests: how protected his funds and data are, how predictable the rules are, and how stable this protection remains when interacting with government agencies and regulators. Our task is to choose a legal environment in which the client can freely use financial instruments and at the same time be confident that his interests truly matter. Because a good jurisdiction should regulate a financial company, and not turn it into a convenient tool for accessing the money and information of its clients.
So today it is not enough to simply choose a bank, broker or exchange with a convenient application and low commissions. It is important to find a financial partner to whom you are willing to entrust not only money, but also information about yourself. A partner who provides access to the necessary financial instruments, works in a clear and predictable jurisdiction and does not perceive the client’s interests as the last link in the chain at the first external request. In the modern world, we no longer just choose the place where our money is stored. We choose the one we trust to protect them.
The material was prepared by the editors of ParadTrade.







