Binance, Russia, and User Data: What the Belenkiy Case Means for AML and KYC Compliance
Binance allegedly provided Russian investigators with detailed personal records on a customer who was subsequently charged with financing terrorism for donating small sums to Ukrainian groups. The case, reported by Reuters and covered by CoinDesk, is not merely a geopolitical story. It is a compliance stress test for every accounting firm, auditor, and CFO whose clients hold accounts on centralised exchanges, anywhere that a government with contested legal standards can submit a data request and receive a response.
What the Documents Show
According to reporting by Reuters, which reviewed law enforcement documents obtained by The First Department, a Russian organisation that supports defendants in political cases, Binance responded at least twice to requests from Russia's Investigative Committee. The documents were sourced from a relative of the subject, Yuri Belenkiy, a Russian IT specialist.
The personal data disclosed
The data allegedly handed over went well beyond transactional records. Investigators reportedly received Belenkiy's date of birth, home address, phone number, and passport number, along with copies of his Russian passport and Bulgarian residency permit. Binance also identified him as the originator of transfers totalling more than $700, according to Reuters.
The underlying allegation
Russian authorities allege that Belenkiy made payments between January 2023 and March 2024 following an appeal by Arkady Babchenko, an exiled Kremlin critic. The funds were reportedly directed toward the Ukrainian military and a group linked to the Azov Brigade. Moscow classifies the Azov Brigade as a terrorist organisation, a designation not recognised by the EU, the US, or most Western jurisdictions. The terrorism financing charge against Belenkiy flows directly from that domestic classification.
Correspondence with Binance was reportedly sent to case@binanceholdings.ru, an address that Binance's own website had listed for Russian and Belarusian law enforcement agencies.
Binance's Position and the 2023 Russia Exit
Binance sold its Russian business in September 2023, stating publicly that operating there no longer aligned with its compliance strategy. The exchange said at the time that it would retain no revenue-sharing arrangement or option to repurchase the business. That exit was widely read as a deliberate effort to reduce sanctions and AML exposure.
The gap between exit and data retention
The Belenkiy timeline complicates that narrative. The alleged transfers took place between January 2023 and March 2024, meaning some activity occurred both before and after the Russia exit. The data requests from Russian investigators, and Binance's alleged responses, therefore span the transition period, raising questions about what data Binance continued to hold after the exit, under what legal framework that data was retained, and which jurisdiction's law governed the exchange's obligations when Russian investigators submitted their requests.
Binance has stated publicly that it cooperates with lawful law enforcement requests, subject to applicable legal, privacy, and regulatory requirements. The exchange declined to address Belenkiy's case specifically or to confirm whether the disclosures may have conflicted with European data protection rules. CoinDesk reported that it had not received a response from Binance at the time of publication.
Why This Is an AML and KYC Problem, Not Just a PR One
Accounting firms and CFOs may be tempted to read this as a reputational issue for Binance and move on. That would be a mistake. The case exposes structural tensions inside the data-sharing frameworks that underpin KYC and AML compliance for any entity that uses centralised exchanges as part of its digital asset infrastructure.
Whose "lawful request" governs?
The core compliance question here is definitional. When Binance says it responds to "lawful" requests, the word "lawful" is doing enormous work. A request from Russia's Investigative Committee may be lawful under Russian domestic law. It may also be incompatible with the EU General Data Protection Regulation if the subject holds European residency, as Belenkiy did through his Bulgarian permit. It may further conflict with the spirit, if not the letter, of Western sanctions policy if the prosecution is politically motivated and the alleged offence would not constitute a crime in any EU or G7 jurisdiction.
For firms relying on exchanges to serve as the first line of KYC defence, this case is a reminder that the exchange's definition of a lawful request and your jurisdiction's definition may not overlap. That gap is a compliance liability, not an abstraction.
GDPR exposure for EU-linked data subjects
Belenkiy held Bulgarian residency, which places him within the GDPR's territorial scope. Article 48 of the GDPR restricts the transfer of personal data to a third country's authorities without an adequacy decision, appropriate safeguards, or a recognised derogation. Russia does not have an EU adequacy decision. If Binance processed and disclosed his data without a valid legal basis under EU law, the exchange faces potential exposure under GDPR enforcement mechanisms, and any firm that shares client data with exchanges operating under similar policies inherits a reputational and due diligence dimension of that risk.
The terrorism classification asymmetry
Moscow's designation of the Azov Brigade as a terrorist organisation is not mirrored by the EU, the US, or the UK. This asymmetry matters significantly for AML screening. Firms using crypto accounting software or digital asset accounting software that relies on sanctions and terrorist-financing lists must ensure those lists reflect their home jurisdiction's designations, not the designations of third-country governments. Failing to do so can produce false positives that freeze legitimate transactions, or worse, create a compliance paper trail that implies endorsement of a foreign classification standard.
What Accounting Firms and CFOs Should Do Now
This case does not require firms to stop using centralised exchanges. It does require them to treat exchange relationships as a compliance risk category, not a neutral operational choice. The following steps are grounded in the facts of this case and existing regulatory expectations under EU AML directives and GDPR.
Review exchange data-sharing policies as part of vendor due diligence
Most firms conduct KYC on their own clients but do not apply the same rigour to the exchanges those clients use. A basic vendor due diligence review of a major exchange should now include its published law enforcement response policy: which jurisdictions it responds to, what legal threshold it applies before disclosing personal data, and whether its stated policy has been tested in court or by regulators. If an exchange lists a dedicated email address for Russian or Belarusian law enforcement requests, that is material information.
Map client exposure to jurisdictions with divergent legal standards
Clients with dual residency, offshore accounts, or business operations in jurisdictions that conflict with EU or UK law present an elevated profile. The Belenkiy case is a concrete illustration of how a Bulgarian residency permit and a Russian passport, combined with a crypto account on a global exchange, can intersect with Russian law enforcement in ways that no Western compliance framework anticipated. Firms running crypto bookkeeping software for multi-jurisdictional clients should flag this combination and document their assessment.
Separate AML screening lists by jurisdiction
If your AML or transaction monitoring process incorporates any third-party list that includes designations from non-EU, non-UK, or non-US authorities, audit it now. The terrorism financing charge against Belenkiy would not exist under Western law. Any screening tool that treats Moscow's Azov designation as equivalent to a UN or OFAC listing is importing a legal standard that conflicts with your home jurisdiction's obligations and could expose your firm to reputational and regulatory risk.
Document the geopolitical dimension in your risk appetite statement
EU AML rules, including those being tightened under the forthcoming AMLA framework, require firms to articulate their risk appetite and apply enhanced due diligence where higher risk is identified. The Binance-Russia data case is now a matter of public record. Failing to acknowledge geopolitically driven law enforcement risk in your documented risk appetite, particularly for clients with Russian or Belarusian connections, would be difficult to defend in a supervisory review.
For additional context on how Russian-linked crypto flows have intersected with sanctions evasion, see our earlier coverage of what the A7 stablecoin leaks revealed about Russian sanctions evasion and AML gaps. On the analytical tools available to compliance teams, our piece on how blockchain analytics tools are reshaping AML compliance for accounting firms sets out the current state of on-chain monitoring.
The Broader Signal for the Industry
The Belenkiy case is unlikely to be the last of its kind. As crypto adoption expands into jurisdictions with authoritarian legal systems, the tension between a global exchange's obligation to cooperate with local law enforcement and its obligations under EU, US, or UK law will recur. The case also highlights a structural feature of centralised exchanges that is often underweighted in compliance discussions: they are repositories of highly sensitive personal data, and that data does not disappear when an exchange exits a market.
For accounting firms and CFOs using any form of crypto accounting software to manage digital asset positions, the relevant question is not whether your exchange was involved in this specific case. The question is whether you have reviewed the law enforcement disclosure policies of every exchange your clients use, and whether those policies are compatible with your jurisdiction's data protection and AML obligations. If that review has not happened, this case gives you the grounds and the urgency to initiate it.
Frequently Asked Questions
Did Binance break EU law by sharing Belenkiy's data with Russian authorities?
That remains unconfirmed and is likely to depend on the specific legal basis Binance relied upon. GDPR Article 48 restricts personal data transfers to foreign authorities without adequate legal grounds. Russia does not hold an EU adequacy decision. Binance has not publicly confirmed the legal basis it applied, and no EU regulator has yet announced an investigation. The question is live and unresolved.
Does this affect firms that are not directly using Binance?
Yes, indirectly. The case establishes a documented precedent that major exchanges will respond to law enforcement requests from jurisdictions with divergent legal and political standards. Any firm whose clients use centralised exchanges faces the same structural exposure, regardless of which exchange is involved, if that exchange operates in or retains data connected to politically sensitive jurisdictions.
Is donating to Ukrainian groups a criminal offence under international law?
Not under EU, US, or UK law. The charge against Belenkiy is based on Russia's domestic classification of the Azov Brigade as a terrorist organisation, a designation not recognised by Western governments or international bodies. Western AML frameworks would not flag such donations as terrorism financing.
What should firms do if a client holds accounts on an exchange that lists a Russian or Belarusian law enforcement contact address?
Treat that as an elevated-risk indicator in your vendor due diligence process. Document your assessment, consider whether enhanced due diligence applies to that client relationship, and review your firm's obligations under applicable data protection and AML rules. If the client is EU-resident or EU-domiciled, the GDPR dimension is particularly relevant.
How does this case interact with the EU's upcoming AMLA framework?
The EU's new Anti-Money Laundering Authority is expected to introduce stronger supervisory standards for crypto asset service providers operating across member states, including requirements around data governance and law enforcement cooperation. The Belenkiy case illustrates exactly the kind of jurisdictional conflict that AMLA-era rules are designed to address. Firms should monitor AMLA guidance as it develops and ensure their internal policies can accommodate stricter standards on third-country data transfers.
Source: CoinDesk
