
Revolut disclosed clients’ passports, verification selfies and Bitcoin transaction histories after treating a fraudulent authorities request as respectable.
Affected clients had been advised Friday that the disclosed data might embrace passport or driver’s license copies, verification selfies, names, dates of beginning, occupations, residence addresses, cellphone numbers, IBANs, and account statements. Withdrawal data and full transaction histories, together with Bitcoin exercise, can also have been launched.
The request got here from an unauthorized mailbox working contained in the area infrastructure of a real authorities company and carried legitimate authentication credentials.
Revolut subsequently contacted the company, concluded the request was fraudulent, blocked the handle and started notifying clients and regulators. The corporate has not recognized the company or disclosed what number of clients had been affected.
Compliance calls for sharpen buyer backlash
The incident has drawn scrutiny over how a lot data monetary establishments gather from clients and the controls used when governments later search entry to these data.
Marc Zeller, founding father of the Aave Chan Initiative, stated the disclosure got here shortly after Revolut demanded further data from him, threatening to shut his account.
“The infuriating half is that it occurs proper after Revolut despatched me a notification to offer a LOT of knowledge or ‘we are going to shut your account in 20 days,’” Zeller stated. He accused the corporate of doing the attackers’ work for them after the request fooled him.
The criticism cuts right into a stress created by trendy monetary compliance. Banks and fintech companies gather in depth id and transaction data to fulfill know-your-customer and anti-money laundering necessities. These databases turn into particularly delicate once they hyperlink verified identities and residential data to cryptocurrency exercise.
For Bitcoin holders, the uncovered data might give an attacker excess of a monetary assertion. Bitcoin transactions are recorded on a public blockchain, which means data tying a recognized individual to particular exercise can probably assist map that particular person’s wider onchain footprint.
Onchain investigator ZachXBT, who publicized the incident, stated the disclosure appeared restricted in scale and will have focused high-net-worth clients. Revolut has not supplied a determine that might set up the scope of the incident.
No buyer funds have been reported stolen, and the knowledge described in Revolut’s notices didn’t embrace passwords, card PINs or cryptocurrency non-public keys.
The rapid threat as an alternative stems from the mix of id paperwork, contact data, residential addresses and monetary histories now probably out there to the attacker.
A real authorities area defeated Revolut’s checks
The tactic used to acquire the knowledge leaves a separate drawback for Revolut and probably different monetary establishments that obtained requests from the identical supply.
The fraudulent electronic mail handed SPF, DKIM and DMARC authentication, mechanisms designed to assist confirm that messages are approved by the area they declare to symbolize.
That implies the attacker had entry to an unauthorized mailbox throughout the authorities company’s precise electronic mail infrastructure fairly than merely altering the sender data on a traditional spoofed electronic mail.
Revolut stated that mixture led it to meet the request, believing it got here from an genuine authorities authority. The agency found the issue after contacting the company individually, then alerted officers to the unauthorized mailbox and blocked the sender internally.
Former Mt. Gox CEO Mark Karpelès, who circulated a duplicate of the notification Saturday, argued that figuring out the compromised authorities company might enable different banks and exchanges to find out whether or not additionally they obtained data calls for from the identical mailbox. Revolut has thus far withheld the company’s id whereas it investigates.
That leaves the verification sequence as the important thing unresolved challenge. Revolut has defined why the e-mail appeared genuine, however has but to say whether or not authorities data requests require affirmation outdoors electronic mail, why it contacted the company solely after releasing buyer data, or whether or not it has modified that course of since discovering the fraud.



