A European neobank suffers a BEC attack. What happens to the leaked data?
A European neobank with a global presence confirmed on September 12 that it had handed over personal information belonging to some of its customers to an unauthorized third party. It was not a hack: the company responded to a data request that came from a government agency’s email domain and treated it as genuine, in what is known as a BEC attack. According to reports, the attack may have originated in Italy, where the attackers allegedly used infrastructure belonging to the country’s own authorities, although this has not been officially confirmed.
According to the notification sent to those affected, the compromised information went beyond names and phone numbers. It included dates of birth, addresses, copies of identity documents such as passports and driver’s licenses, and in some cases verification selfies, account statements, and transaction histories. The company described the scope as “limited,” said it had notified each affected customer individually, and reported the incident to the impersonated agency, law enforcement, and regulators. Its systems and customers’ money were not affected.
That last detail is reassuring, and it is true. But the problem with this data breach is not the money that did not move, but the identities that were exposed.
BEC (Business Email Compromise): A Technique That Is Nothing New
This method has been working for years, and not only against fintechs. In 2021 and 2022, Bloomberg and researcher Brian Krebs documented how Apple, Meta, and Discord handed over user data in response to forged emergency requests, sent from previously compromised law enforcement email accounts. The scheme was the same one at play now: instead of forcing the system, the attacker gets someone on the inside to open the door.
Official figures place this fraud at the center of the problem. The 2025 IC3 Annual Report, from the FBI’s Internet Crime Complaint Center, attributes close to 85% of losses to fraud that exploits human trust rather than technical failures. Government impersonation, the exact category behind this case, accounted for USD 797.9 million, double the previous year.
According to INTERPOL’s report on financial fraud trends, Business Email Compromise ranks first among the five fraud types it identifies as predominant worldwide. It describes BEC as one of the most widespread and costly fraud types, with the highest-value losses concentrated in North America and Europe, where corporate transaction volumes run highest.
The mechanism doesn’t require breaking into any system. It only takes someone inside the organization believing the message is legitimate. This is social engineering, plain and simple, and today it’s just one of several entry points into the same problem. An organization’s data can also leak through channels nobody is monitoring, such as unauthorized use of AI tools.
Once leaked, data stays available indefinitely for the next fraud attempt: synthetic-identity account openings, takeovers of existing accounts, injection attacks that feed manipulated video into verification processes, or deepfakes.
What Happens to That Data Now?
For the rest of the sector, this case leaves two separate fronts to address. One is internal process: verifying any data request through an alternative channel, and not trusting the sender, however legitimate it looks. The other, the one that matters here, is what to do so that once that data is in circulation, it stops being useful to an attacker at the next checkpoint.
That’s where continuous identity comes in. A genuine document and a real photo of its holder can end up in someone else’s hands, and when that happens, checking once that “the photo matches the ID” stops proving much, because an attacker can present exactly that: stolen pieces that match each other. Verification stops being a one-time step at the start of the relationship and becomes a process repeated at every relevant interaction, each time confirming whether there’s a live person present, rather than a document and a face already compromised by another incident.
The technical benchmark for measuring that resistance is the ISO/IEC 30107-3 standard, which evaluates a biometric system’s resilience against presentation attacks (photos, videos, or masks), certified by iBeta, a lab accredited by NIST. Facephi adds injection attack detection to that layer, aimed at fraud that no longer shows up in front of the camera but gets inserted directly into the data flow.
None of these defenses would have stopped someone from answering the email, because the failure was in the process, not in verification. But the lesson the sector can apply going forward is a different one. Identity has to be verified on the assumption that the user’s document and face may already be compromised and in circulation. In 2026, that’s the safer assumption to make.