Sumsub's Ownership Gap: The Identity Verifier That Couldn't Verify Its Own Owners
Sumsub has scanned the passports, faces, and government IDs of users across more than 4,000 client businesses. Each of those clients relies on Sumsub to answer a question they can't answer on their own: who is this person, really?
The company's credentials look flawless on paper. Gartner named it a Leader in its first Magic Quadrant for identity verification, and in January 2026 it joined the World Economic Forum's Unicorn Community. What's missing from that resume is scrutiny of Sumsub itself.

Two facts rarely get placed side by side. First: the entity that controlled Sumsub's UK operating company vanished from the public corporate record — a filing made on October 3, 2023 and only reversed on May 24, 2024. Second: an intruder sat inside Sumsub's systems for roughly a year and a half without being detected. The company disclosed in February 2026 that the breach had actually begun in July 2024.
Sumsub's entire business rests on a simple pitch — you can't extend trust to strangers, so let Sumsub do the verifying for you. The uncomfortable footnote is that nobody applied the same standard to Sumsub. This piece was tipped to Rekt News by Dyma Budorin, CEO of Core3 and co-founder and chairman of Hacken.
01Why a Verifier's Own Record Matters
Compliance teams outsource identity checks because unverified counterparties bring fraud, sanctions exposure, and laundered money along with them. Sumsub built itself into the gatekeeper role that solves that problem for others: over 4,000 clients, 987 employees, and offices spanning London, Berlin, Miami, Singapore, Dubai, and Limassol. Its revenue more than doubled in 2024.
The pitch to clients has always been the same: remove fraud and onboarding friction by handing Sumsub the passport scan, the selfie, the proof of address, and letting it absorb the trust problem in-house compliance teams couldn't solve alone. INTERPOL became a partner, and UN research has cited the company's data. Thousands of compliance workflows are now built around Sumsub deeply enough that ripping it out would mean starting over.
That level of embedding turns a vendor into infrastructure — and infrastructure tends to go unquestioned until something breaks. As it turns out, the answers about who actually controls and had access to this infrastructure were sitting in public records the whole time. Almost nobody looked.
02From SMTDP to Sumsub
Before it operated under the Sumsub name, the company existed as SMTDP Tech Ltd, a Cyprus-registered predecessor with three Israeli-national founders. Among its early backers was Ilya Perekopsky, Telegram's VP and formerly VP and COO of VK, Eastern Europe's largest social network.
Perekopsky's involvement went beyond writing a check — he was listed as co-director of SMTDP in Cyprus alongside the founders from the earliest stage. He backed the 2017 Seed round, stayed on through the 2020 Series A, and didn't exit his position until 2022.
That Series A was led by MetaQuotes, a company developed originally in Russia and operating through Cyprus, best known as the maker of MetaTrader. In 2022, Apple pulled MetaTrader from its App Store after reports that scammers were using the platform to defraud victims. Around the same period, MetaQuotes bought out earlier investor Flint Capital's stake — Flint exited at 5.5x — and took over the lead investor position.
When Russia invaded Ukraine in March 2022, Sumsub issued a statement that, read closely, revealed more than it intended: "The few early investors with Russian exposure who retained minor shares in our company have now all left us." That phrasing confirms Russian-linked investors were still shareholders up to the moment the statement was published. Sumsub subsequently ended its Russian operations and relocated staff from Russia and Belarus to its Germany, UK, and Cyprus offices.
None of that sequence is contested. But the cutoff came in 2022 — years after the company had already been collecting government ID data at scale. What the preceding seven years of ownership actually looked like is a separate question.
03Four and a Half Years Under an Undisclosed Owner
Public UK filings show that from April 2019 to October 2023, a Cyprus company called Raritex Trade Ltd held 75% or more of the shares in Sumsub's UK operating entity — majority voting rights and the power to appoint and remove directors, for four and a half years.
Raritex remains active today and continues to hold the SUMSUB trademark registrations in Canada, Australia, and the EU. Its listed director is Andrey Severyukhin, who is also Sumsub's CEO; Raritex's own shareholders are not publicly disclosed.
On October 2, 2023, Raritex was removed as the controlling entity. What happened the very next day is where the story departs from routine corporate housekeeping.
On October 3, 2023, Sumsub filed a statement with UK Companies House declaring that the company "knows or has reasonable cause to believe that there is no registrable person or registrable relevant legal entity" with significant control — in plain terms, a declaration that it didn't know who controlled it. That statement remained on the public register for seven months, until it was withdrawn on May 24, 2024.
On that same day, three individuals were newly listed as Persons with Significant Control: Peter Sever, Yakov Sever, and Andrey Severyukhin — all Israeli nationals residing in Cyprus. No public explanation has ever been offered for what occurred in the seven months between the two filings, who held effective control during that window, or why the initial filing was worded the way it was.
The irony is hard to miss: a company whose entire commercial value proposition is answering "who controls this entity?" on behalf of its clients spent seven months telling a government regulator it could not answer that question about itself.
A parallel gap surrounds the company's Series B, raised around the end of 2022. Sumsub has described that backer only as "a corporate VC fund" — no name, no public filing, no announcement. For a company handling government ID data on behalf of thousands of financial institutions, declining to identify its largest post-2022 institutional investor isn't a minor omission; it's the kind of gap that would trigger a due-diligence flag if Sumsub found it in someone else's file.
04An Intruder Present for Eighteen Months
In July 2024, according to Sumsub's own account, an external threat actor uploaded a malicious attachment through a third-party support ticketing platform, gaining access to an internal environment. Names, email addresses, and phone numbers tied to a subset of customer accounts were exposed.
The intrusion went unnoticed for roughly eighteen months. It wasn't caught by a routine scan, flagged by an outside researcher, or surfaced by a regulator — Sumsub's own internal security audit in January 2026 found the intruder retrospectively, a year and a half after initial access.
Public disclosure came on February 4, 2026. Sumsub's stated position is that no biometric data, ID document images, or government ID information was accessed — the exposure was limited to a support-related environment containing only names, emails, and phone numbers. Ndax, a Canadian crypto exchange, confirmed it was among the affected clients.
Timing added friction to the disclosure. While the breach news was still recent, Sumsub published a blog post highlighting fraud incidents at other companies. On-chain investigator ZachXBT called the move tone-deaf — a firm that had just admitted to an 18-month undetected intrusion publishing a scorecard on everyone else's security failures. Sumsub's reply to Zach opened with: "In our 10-year history, this is the first incident of its kind."
That claim sits alongside a second incident. In March 2025, security researcher Lilith Wittmann reported that an unsecured API belonging to Merkur AG had exposed Sumsub API tokens, allowing unauthorized access to user data. Sumsub attributed that failure entirely to the third-party integrator's misconfiguration, not to its own systems. Two incidents; both attributed elsewhere.
Beyond the specific incidents, the structural risk is what critics keep returning to: centralizing identity verification in a single vendor concentrates risk by design. Any exchange, fintech, or analytics firm that outsources KYC to one provider becomes exposed the moment that provider is breached — potentially all at once, across its entire client roster. As the Zyphe analysis summarized it: "If your KYC vendor is compromised and doesn't know it, you don't know it either, but you're still responsible for the data you've entrusted to them and for the regulatory obligations tied to that data." A company built to verify identities for some of the largest crypto exchanges in the world could not detect an intruder in its own systems for a year and a half.

05What's Still Unanswered
Several questions have no public answer as of this writing:
Who owns Raritex Trade Ltd? The entity that controlled Sumsub's UK company for four and a half years still holds SUMSUB trademarks across multiple jurisdictions, yet its beneficial ownership remains undisclosed.
Who financed the Series B? The round closed in December 2022, after the invasion of Ukraine, after the company's Ukraine statement, and after the Russian-linked investor exits. Sumsub names the backer only as "a corporate VC fund" — no name, no filing, no announcement — despite processing identity data for clients including Bybit, Vodafone, and Duolingo.
What happened between October 2, 2023 and May 24, 2024? For seven months, Sumsub's own UK filing stated it had no identifiable controlling person. The filing was later retracted with no accompanying statement or acknowledgment of the gap.
How many people were affected by the breach? Sumsub has not said. GDPR requires notifying affected individuals and regulators within 72 hours of becoming aware of a breach; Sumsub states it became aware in January 2026, but the number of individuals affected and the status of any regulatory notifications remain undisclosed.
None of these are minor details — each is exactly the kind of question a compliance team is trained to ask before adding a vendor to its verification stack. Individually, each item has a plausible explanation. Taken together, they form the sort of pattern that Sumsub's own screening product would likely flag if it appeared in a client's file.
06The Standard Nobody Applied
Every exchange and fintech that built Sumsub into its onboarding flow did so because it couldn't afford to trust unverified strangers. None of them, apparently, applied that same bar to the company doing the verifying. That's less a Sumsub-specific failure than a structural one: the compliance layer underpinning much of crypto rests on vendors treated as infrastructure — and infrastructure, almost by definition, doesn't get audited until something goes wrong.
The identity checks are still running, and the client list keeps growing. The open questions — who controlled the company during its formative years, who is bankrolling it now, and how long an intruder sat undetected in its systems — remain open. The gate is open for business; whether anyone ever checked who owns it is a separate matter entirely.
Get new scam files the moment we publish them — usually 2–3 emails a week.