
BasedApp, a Singaporean fintech, on Thursday confirmed an intrusion detected on Monday in its internal system related to its Visa card program, potentially exposing some users' KYC data such as name, passport number, date of birth and address, while ensuring that funds, card numbers, CVV and PIN remain intact.
AI-generated summary
BasedApp is a Singaporean fintech application that offers a wallet, trading and a Visa card. Monday, October 5, it detected unauthorized access to an internal dashboard of its Visa card program.
Your papers, please. This Thursday, October 8, BasedApp confirmed an intrusion that occurred at the heart of its infrastructure. In a press release published on X (Twitter), the Singaporean fintech confirms the worst scenario. KYC data of certain Visa card holders could have been stolen. However, the funds remain intact, in a context where Denmark recently identified 8 million national identifiers exposed.
The key points of this article:
On Monday October 5, Based detected that an unauthorized third party was accessing an internal dashboard of its Visa card program.
KYC data of certain holders, including name, passport number, date of birth and address, could have been obtained by the attacker.
Card numbers, CVVs, PINs, ID photos and Based Wallet funds are not affected by the incident.
The company calls on affected customers to be cautious of future spoofing and social engineering attempts.
An intrusion into the heart of the card program
As a reminder, Based (SHA2 Labs) is a Singaporean fintech application that combines wallet, trading and Visa card of the same name. On Monday, the team learned that an unauthorized actor had successfully breached an internal dashboard, used to administer the card program. The attack was “quickly stopped and contained” upon its discovery, assures the company.
In fact, it is the KYC (know your customer) data collected by the card issuer that is targeted. Name, identity document or passport number, date of birth and address appeared in the potentially exposed perimeter. The company specifies that only “certain carriers” are concerned, without disclosing any figures. Separately, affected customers received an email on Thursday, while the relevant authorities were informed of the incident.
Funds intact, but a very real risk of usurpation
On the good news side, the list of elements spared is rather reassuring. Card numbers, CVVs and PINs were not leaked, nor were ID photos and liveness check images. The Based Wallet, which is used for trading, escapes the incident, and the funds on the card remain accessible. Additionally, Visa payments continue to operate normally.
However, identity data is enough to fuel very credible social engineering campaigns.
“If you are one of the affected users, consider this data compromised. »
The team therefore reminds that support goes exclusively through the chat integrated into the application, and that no member will contact users by private message on Telegram or X.
In practice, the press release also assumes a singular choice. The team says it “purposely” disabled comments on the post for security reasons. A way to cut short fake support agents, a classic of the genre. Indeed, the mechanics are known, since a cyberattack targeting Oracle had already exposed the health data of nearly 20 million people last week.
AI outlook — possibilities, not facts
BasedApp will strengthen the security of its internal systems and implement increased monitoring to prevent future intrusions.
Likely · Within weeks

On October 6, Mistral presented its Large 4 multimodal AI model, nicknamed “The Chonk”, equipped with 1,000 billion parameters, including 49 billion active ones. The Parisian company claims that it exceeds GPT-6 Astra in finance but remains behind Claude in other areas, while putting forward its argument of European sovereignty and a competitive price for massive uses.

Denmark faces a hack of its central CPR register, exposing the data of 8.8 million people. This incident reignites the debate on the security of state databases and digital identity wallets.

ZachXBT claims to have used $3.5 million of its own funds to infiltrate a Chinese money laundering network suspected of working for the North Korea-linked Lazarus Group. His investigation, revealed on October 5, made it possible to identify addresses associated with more than $12 million from the Bybit hack and to obtain the freezing of 442,000 USDT by Tether.

The Danish government announced on Monday the leak of the data of nearly 8.8 million people registered in the central population register, consulted illegally via access from a private company.

Near Intents has recovered all of the $3.8 million stolen in an attack on its cross-chain swap service, following a 48-hour ultimatum from its chief executive.

In the third quarter of 2026, cryptocurrency hacks resulted in the theft of $1.26 billion according to CertiK, despite a 40% increase in bitcoin over the same period. September was the worst month with $768.5 million lost, mainly due to code and infrastructure flaws. Net losses after recoveries amounted to 869.6 million for the quarter, while the sector's insurance capacity fell by 20% year-on-year. Major attacks have targeted Bitget, Liquid Network and Tectonic, exploiting vulnerabilities in third-party providers, cryptographic proofs and lending protocols. AI now accelerates the detection of flaws in smart contracts.