BasedApp disclosed a data breach exposing customer KYC data including names, dates of birth, addresses, and passport numbers. Unauthorized parties also gained administrator access to the company's AI-agent backend through Google Quick Login, compromising sensitive tokens and API keys.