Summary: Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers

Published: 7 hours ago
Based on article from CryptoSlate

Revolut Data Disclosure: A Sophisticated Breach via Government Infrastructure

The fintech giant Revolut recently disclosed a troubling security incident in which sensitive customer data was released to unauthorized third parties. The breach was the result of a fraudulent request disguised as a legitimate government inquiry, highlighting the growing complexity of cyberattacks targeting global financial institutions.

A Breach of Trust Through Genuine Infrastructure

The incident was uniquely effective because the fraudulent request originated from an unauthorized mailbox within the actual domain infrastructure of a genuine government agency. By utilizing valid authentication credentials—including SPF, DKIM, and DMARC—the attackers successfully tricked Revolut’s compliance team into believing the demand was a legitimate legal mandate. As a result, the company inadvertently shared a treasure trove of sensitive information, including passport copies, driver’s licenses, verification selfies, and comprehensive Bitcoin transaction histories.

The Controversy of Mandatory Data Collection

This disclosure has sparked significant backlash regarding the aggressive "Know Your Customer" (KYC) and anti-money laundering (AML) protocols that modern banks enforce. Affected customers have expressed frustration that they are often pressured to provide extensive personal data under the threat of account termination, only for that data to be mismanaged. The exposure is especially concerning for cryptocurrency users, as linking verified identities to public blockchain activity can expose an individual’s entire on-chain financial footprint, creating a permanent security risk that extends far beyond a simple bank statement.

Unresolved Questions and Future Safeguards

While Revolut has blocked the fraudulent address and notified regulators, several critical questions remain unanswered regarding the scale of the leak. The company has yet to identify the compromised government agency or specify the exact number of affected users, though investigators suggest the breach may have specifically targeted high-net-worth individuals. Furthermore, the incident raises urgent concerns about whether financial institutions should rely solely on email verification for sensitive data transfers and whether more rigorous, multi-factor authentication processes are needed for government information requests.

Cookies Policy - Privacy Policy - Terms of Use - © 2025 Altfins, j. s. a.