Skip to main content
AVOID.NET
Transakreviewed 2026-09-07 · 25 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Transak against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

2 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #10[disputed][awaiting moderator]in section: October 2024 Data Breach
    CEO Sami Start stated: 'No bank statements, social security numbers, or credit card details were accessed, and even emails or passwords were not involved, which significantly reduces the severity of the incident.'
    reviewerCEO Sami Start stated: 'No bank statements, social security numbers, or credit card details were accessed, and even emails or passwords were not involved, which significantly reduces the severity of the incident.'This is presented as a direct quotation but does not match the verbatim wording reported by CoinDesk, which quotes Start as saying, in full: "There's no bank statements, there's no social security numbers, there's no credit card information, there's not even any emails or passwords that were accessed, which limits the severity of this incident significantly." The substance is materially the same but the exact wording attributed to a named individual is inaccurate.
    Proposed correction (not yet applied)
    CEO Sami Start stated: "There's no bank statements, there's no social security numbers, there's no credit card information, there's not even any emails or passwords that were accessed, which limits the severity of this incident significantly."
  2. #14[disputed][awaiting moderator]in section: Stormous Ransomware Group Claims
    CEO Sami Start acknowledged uncertainty about the group's claims, stating: 'We don't know if they necessarily did this or if they're just claiming credit for it.'
    reviewerCEO Sami Start acknowledged uncertainty about the group's claims, stating: 'We don't know if they necessarily did this or if they're just claiming credit for it.'Same issue as the other CEO quotation in this investigation: the substance is accurate but the exact wording attributed to Start in quotation marks does not match verbatim reporting.
    Proposed correction (not yet applied)
    CEO Sami Start acknowledged uncertainty about the group's claims, stating: "We don't know if they actually did it or they are just taking the credit for it."

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #21[unverifiable][awaiting moderator]in section: Regulatory Notifications and Compliance Response
    As of the time of this report, no regulatory enforcement actions or fines against Transak related to the October 2024 breach have been publicly reported.
    reviewerAs of the time of this report, no regulatory enforcement actions or fines against Transak related to the October 2024 breach have been publicly reported.This is a claim of absence (no enforcement action found). No public reporting of ICO, EU, or US enforcement action was found in this review, consistent with the claim, but a negative cannot be fully confirmed without direct access to each regulator's enforcement register.

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #15[partially supported][awaiting moderator]in section: ZachXBT Coverage
    ZachXBT also noted the connection between the Stormous group's Transak attack and the same group's earlier breach of Fractal ID in July 2024, suggesting a pattern of targeting crypto identity infrastructure.
    reviewerZachXBT noted the connection between the Stormous group's Transak attack and the same group's earlier breach of Fractal ID in July 2024.The underlying claim appears to be true and is corroborated by other outlets, but the single source cited for this section does not itself support the Fractal ID connection attributed to ZachXBT. The citation should be supplemented or replaced with a source that actually makes this connection.
  2. #18[partially supported][awaiting moderator]in section: Class Action Lawsuit and Settlement
    The lawsuit received preliminary court approval for a $601,000 settlement on September 7, 2025.
    reviewerThe lawsuit received preliminary court approval for a $601,000 settlement on September 7, 2025.The settlement amount and September 7, 2025 preliminary-approval date are accurate, but the paragraph reads as a single continuous case when the settlement was in fact reached and approved under a different case number and court (a Broward County Circuit Court action) than the federal case described for the original March 2025 filing. This venue/case-number distinction is verifiable from the settlement notice itself and is currently omitted, which could mislead a reader trying to look up docket status.
  3. #25[partially supported][awaiting moderator]in the timeline
    The Pearson v. Transak USA class action received preliminary court approval for a $601,000 settlement covering 23,113 U.S.-based affected individuals.
    reviewerThe Pearson v. Transak USA class action received preliminary court approval for a $601,000 settlement covering 23,113 U.S.-based affected individuals on September 7, 2025.Same underlying issue as the corresponding section finding: the timeline entry implies continuity with the federal case (1:25-cv-21146) without noting that preliminary approval was actually granted in a separate Broward County Circuit Court action.

confirmed

19 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    Transak is a fiat-to-crypto on-ramp infrastructure provider founded in 2019 and serving over 8 million users across 160+ countries, with integrations into major platforms including MetaMask, Phantom, and Uniswap.
    reviewerTransak is a fiat-to-crypto on-ramp provider founded in 2019, serving over 8 million users across 160+ countries, integrated with MetaMask, Phantom, and Uniswap.Founding year, integrations and general description are well-corroborated across multiple sources. Current 8M+ users / 160+ countries figures reflect more recent company marketing than the specific DL News article cited, but are independently corroborated by other current sources.
  2. #2[confirmed][no action needed]in the summary
    In October 2024, a phishing attack on an employee's laptop led to unauthorized access to a third-party KYC vendor's dashboard, exposing the personal identity documents of approximately 92,554 users globally, including names, dates of birth, government-issued IDs, and selfie photos.
    reviewerIn October 2024, a phishing attack on an employee's laptop led to unauthorized access to a third-party KYC vendor's dashboard, exposing personal identity documents of approximately 92,554 users.Well-corroborated across Transak's own disclosure and multiple independent outlets.
  3. #3[confirmed][no action needed]in the summary
    The breach resulted in a $601,000 class action settlement covering U.S.-based affected users, and the Stormous ransomware group claimed responsibility, alleging extraction of over 300GB of data.
    reviewerThe breach resulted in a $601,000 class action settlement covering U.S.-based affected users, and Stormous claimed responsibility, alleging extraction of over 300GB of data.Settlement amount and Stormous claim are both confirmed, though see separate finding on the settlement's actual case/venue.
  4. #4[confirmed][no action needed]in section: Company Overview
    Transak is a fiat-to-crypto payment infrastructure provider founded in 2019 by Sami Start (CEO) and Yeshu Agarwal.
    reviewerTransak was founded in 2019 by Sami Start (CEO) and Yeshu Agarwal.Multiple independent sources corroborate 2019 founding by Start and Agarwal.
  5. #5[confirmed][no action needed]in section: Company Overview
    The company enables users in 160+ countries to purchase cryptocurrency using fiat currency, supporting 100+ cryptocurrencies across 75+ blockchains.
    reviewerTransak enables users in 160+ countries, supports 100+ cryptocurrencies across 75+ blockchains, integrates with over 350 platforms, and claims over 8.3 million users.Cryptocurrency/blockchain coverage figures match the cited DL News article precisely. Country and platform/user counts are corroborated by independent current sources, though not by the specific article's own (lower, older) figures.
  6. #6[confirmed][no action needed]in section: Company Overview
    The company has raised $37 million in funding from investors including Tether, IDG Capital, and ConsenSys.
    reviewerTransak has raised $37 million in funding from investors including Tether, IDG Capital, and ConsenSys.$37M is an aggregate across multiple rounds rather than a single round; the named investors are each independently confirmed.
  7. #7[confirmed][no action needed]in section: Company Overview
    Transak operates registered entities in the USA, UK, Canada, Australia, Poland, India, and Hong Kong. Transak Limited, a subsidiary, is registered with the UK's Financial Conduct Authority (FCA) as a crypto asset firm.
    reviewerTransak operates registered entities in the USA, UK, Canada, Australia, Poland, India, and Hong Kong, and Transak Limited is registered with the UK FCA as a crypto asset firm.Registered-entity footprint and FCA registration independently confirmed via the FCA's own public register.
  8. #8[confirmed][no action needed]in section: Company Overview
    In March 2024, Transak announced it became the first crypto on-ramp provider to achieve SOC 2 Type 2 compliance.
    reviewerIn March 2024, Transak announced it became the first crypto on-ramp provider to achieve SOC 2 Type 2 compliance.Date and 'first' claim are corroborated by independent trade press, not just Transak's own announcement.
  9. #9[confirmed][no action needed]in section: October 2024 Data Breach
    In October 2024, Transak disclosed a data breach affecting 92,554 users, representing approximately 1.14% of its user base.
    reviewerTransak disclosed a data breach affecting 92,554 users (~1.14% of user base) via phishing of an employee's laptop leading to third-party KYC vendor access; no financially sensitive data was compromised; the responsible employee was dismissed.Core breach mechanics, scope, and remediation claims are consistently corroborated across Transak's own blog and independent outlets.
  10. #11[confirmed][no action needed]in section: October 2024 Data Breach
    Transak notified relevant data protection authorities including the UK's Information Commissioner's Office (ICO) and regulators across the EU and US, and offered identity monitoring services to affected users.
    reviewerTransak notified the UK ICO and regulators across the EU and US, and offered identity monitoring services to affected users.Consistent with Transak's official disclosure language and independent reporting.
  11. #12[confirmed][no action needed]in section: October 2024 Data Breach
    Transak's documentation confirms an integration with Sumsub for KYC reliance, though the company has not publicly named the specific vendor compromised in this incident.
    reviewerTransak's documentation confirms an integration with Sumsub for KYC reliance, though the company has not publicly named the specific vendor compromised.Page correctly avoids asserting Sumsub was the compromised vendor; this is an appropriately hedged claim.
  12. #13[confirmed][no action needed]in section: Stormous Ransomware Group Claims
    The Stormous ransomware group claimed responsibility for the Transak breach, alleging the extraction of over 300GB of data from Transak's systems.
    reviewerStormous claimed extraction of over 300GB of data and published a leak page around October 31, 2024, claiming broader data categories (financial statements, proof of address) than Transak's official disclosure; Stormous had previously claimed the July 2024 Fractal ID breach.Stormous's claims, leak-page timing, broader data scope, and the Fractal ID precedent are all independently corroborated.
  13. #16[confirmed][no action needed]in section: Class Action Lawsuit and Settlement
    On March 11, 2025, plaintiff Shane Pearson filed a class action lawsuit against Transak USA LLC in the US District Court for the Southern District of Florida (Case No. 1:25-cv-21146).
    reviewerOn March 11, 2025, Shane Pearson filed a class action against Transak USA LLC in the US District Court for the Southern District of Florida, Case No. 1:25-cv-21146, alleging negligence, breach of third-party contract, invasion of privacy, and unjust enrichment.The initial federal filing details (plaintiff, date, court, case number, causes of action) are all confirmed.
  14. #17[confirmed][no action needed]in section: Class Action Lawsuit and Settlement
    The U.S. breach was reported to have affected 23,113 individuals — a subset of the broader global 92,554-user figure — with data including full names, addresses, driver's license numbers, and dates of birth.
    reviewerThe U.S. breach affected 23,113 individuals, a subset of the global 92,554-user figure, with exposed data including full names, addresses, driver's license numbers, and dates of birth.23,113-individual figure and data categories are consistent across legal-news aggregators and the official settlement notice.
  15. #19[confirmed][no action needed]in section: Class Action Lawsuit and Settlement
    Under the settlement terms, class members with documented out-of-pocket losses such as identity theft remediation or credit monitoring expenses may claim up to $1,500; those without documentation may receive $50.
    reviewerClass members with documented out-of-pocket losses may claim up to $1,500; those without documentation may receive $50; the claim deadline was December 1, 2025, with a final approval hearing on December 15, 2025.Settlement mechanics independently verified against the primary settlement notice document.
  16. #20[confirmed][no action needed]in section: Third-Party Vendor Risk
    This breach follows a similar pattern to the Fractal ID breach in July 2024, also claimed by Stormous, and a Sumsub-related data leak reported in early 2026, indicating broader vulnerability across shared KYC infrastructure in the Web3 sector.
    reviewerThis breach follows a similar pattern to the Fractal ID breach in July 2024, also claimed by Stormous, and a Sumsub-related data leak reported in early 2026.Both referenced incidents (Fractal ID/Stormous, and the 2026 Sumsub incident) are independently confirmed, though the Sumsub incident's root cause (a malicious support-ticket attachment) differs mechanically from Transak's phishing/vendor-dashboard vector; the page's framing as a shared 'pattern' is a reasonable but general characterization.
  17. #22[confirmed][no action needed]in the timeline
    Transak was first contacted by a hacker claiming to have accessed confidential data from its network (per U.S. class action filing).
    reviewerTransak was first contacted by a hacker claiming to have accessed confidential data from its network on September 23, 2024.Date and characterization are corroborated by the underlying legal filings.
  18. #23[confirmed][no action needed]in the timeline
    Reported date of the phishing-enabled breach of a Transak employee's laptop and subsequent access to a third-party KYC vendor's dashboard.
    reviewerThe phishing-enabled breach of a Transak employee's laptop and subsequent access to the KYC vendor's dashboard is reported to have occurred on October 20, 2024.October 20, 2024 date for the underlying attack is corroborated by independent reporting distinct from the October 21 public-disclosure date.
  19. #24[confirmed][no action needed]in the timeline
    Transak announced SOC 2 Type 2 compliance certification, claiming to be the first crypto on-ramp provider to achieve this standard.
    reviewerTransak announced SOC 2 Type 2 compliance certification on March 7, 2024.Date field (2024-03-07) matches independent reporting of the announcement date.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.