Reuters Finds Binance Gave Russia Customer Data Used in Ukraine Donations Case
Key Takeaways
- •A Reuters investigation found that Binance voluntarily handed a customer's personal and transaction records to Russian authorities in 2025, despite having fully exited the Russian market in 2023.
- •The data was used in a case against Yuri Belenkiy, an IT specialist detained in 2025 and accused by Russia of terrorist financing for sending more than $700 to the Ukrainian military and the Azov unit between January 2023 and March 2024.
- •Legal experts say Binance had no obligation to provide the data after leaving Russia and may have been prohibited from doing so under EU GDPR rules, given Belenkiy's Bulgarian residence permit.
- •Binance told Reuters it was responding to a lawful request and that responsibility for how the data was used lies with Russian authorities, while declining to address possible GDPR violations.
- •As of July 1, 2026, Binance can no longer legally provide services in the EU after the MiCA transition period expired and the exchange withdrew its license application in Greece and suspended core EU services.

In 2023, Binance, then the world’s largest cryptocurrency exchange, announced that it was fully exiting Russia after the country’s 2022 full-scale invasion of Ukraine and the Western sanctions imposed on Moscow. Leaving the market meant the exchange was no longer required to hand over customer data to Russian authorities.
Yet a recent Reuters investigation found that in 2025 Binance had voluntarily provided Russian authorities with a customer’s personal and transaction records. That information was later used as evidence in a case against him involving donations to the Ukrainian military. When a company no longer has a presence in a country, governments seeking its records generally rely on formal state-to-state channels such as mutual legal-assistance treaties.
A Donation Becomes a Terrorism Case
Yuri Belenkiy, an IT specialist who holds a Russian passport and a Bulgarian residence permit, was detained by Russian authorities in 2025.
Russia’s Investigative Committee accused him of sending more than $700 to the Ukrainian military and to an affiliated unit known as Azov, which Russia designates as a terrorist organization. The payments allegedly took place between January 2023 and March 2024.
Russia’s criminal code defines terrorist financing broadly, covering transfers to individuals or organizations on the state’s “terrorist and extremist” list. That list includes anti-corruption, LGBT, opposition and media organizations. Ukraine and Western governments, by contrast, regard Azov as a legitimate military formation. In 2024, the U.S. State Department lifted a ban that had barred the brigade from using American weapons, saying it found no evidence of gross violations of human rights under the Leahy Law.
Amnesty International said in 2024 that more than 90% of cases brought under Russia’s anti-terrorism laws involved no actual or planned terrorist attack, but instead concerned online comments or donations to opposition groups.
Russia has also faced international allegations of war crimes and crimes against humanity over its invasion of Ukraine. In 2023, the International Criminal Court issued an arrest warrant for President Vladimir Putin over the alleged unlawful deportation and transfer of Ukrainian children to Russia. The same year, then-U.S. Secretary of State Antony Blinken said Russian forces and other Russian officials had committed crimes against humanity in Ukraine.
Binance Defends the Disclosure
Because Belenkiy holds a Bulgarian residence permit, questions have been raised about which data protection rules applied to his account. According to Mike Bystrov, founder of law firm Stellar Consulting, which advises on crypto regulation, Binance was under no obligation to provide his data to Russian authorities after leaving the Russian market and may have been prohibited from doing so under EU data protection law.
If Belenkiy was registered with Binance as an EU resident, he would be covered by the bloc’s General Data Protection Regulation (GDPR). That regime would prohibit Binance from disclosing his details without a court order and compliance with very stringent provisions. In force since 2018, GDPR allows national data-protection authorities to impose fines of up to €20 million or 4% of a company’s global annual turnover, whichever is higher, and it separately restricts transfers of EU residents’ personal data to countries outside the bloc. Russia has never received an EU adequacy decision recognizing its data-protection regime as equivalent.
Binance told Reuters it was only responding to a lawful request and that Russian authorities, not Binance, were responsible for how the data was used. The exchange did not say whether providing Belenkiy’s data to Russian authorities could have violated GDPR rules. Reuters could not determine whether Belenkiy was registered with Binance as an EU customer.
Binance’s position in Europe has since changed. As of July 1, 2026, the exchange can no longer legally provide services in the EU after the transition period under the bloc’s MiCA regulatory framework expired. MiCA, the EU’s Markets in Crypto-Assets Regulation, became fully applicable at the end of 2024 and created a single licensing passport for crypto-asset service providers across the bloc, with member states allowed to run transitional windows for firms already operating before it. Since then, crypto exchanges without a CASP license have been barred from legally offering services across the European Economic Area. In late June, Binance withdrew its MiCA license application in Greece and suspended core services for EU users.
Binance Left Russia. Russian Authorities Still Got Its Data
Russia invaded Ukraine in February 2022, triggering Western sanctions that targeted Russian banks and the country’s access to global financial markets. After the invasion, Binance stopped accepting Russia-issued Visa and Mastercard cards and restricted accounts with balances above €10,000.
In September 2023, Binance announced it was fully exiting the Russian market and selling its business to CommEX. The new platform looked strikingly similar to Binance, raising questions about whether the exchange had truly left Russia. Then-CEO Changpeng Zhao even said BNB users would continue to receive a 25% discount on trading fees on CommEX. Two months later, Zhao stepped down as CEO after Binance pleaded guilty to U.S. anti-money-laundering and sanctions violations and agreed to pay $4.3 billion, one of the largest corporate penalties in U.S. history.
CommEX shut down its operations in 2024. That September, Binance confirmed it was still serving a limited number of Russian users, citing the need to protect their assets.
Why This Matters
The case shows that leaving a country commercially does not necessarily end a company’s data relationship with that country’s authorities. It raises questions about how far compliance obligations extend once a firm says it has exited a market.