Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers

Revolut recently faced a data breach that resulted in the disclosure of customers’ sensitive information, including passports, verification selfies, and Bitcoin transaction histories. The breach occurred when the company mistakenly treated a fraudulent government request as legitimate.

Affected customers were notified that the exposed information could include copies of passports or driver’s licenses, verification selfies, personal details such as names, dates of birth, occupations, home addresses, phone numbers, IBANs, and account statements. Additionally, withdrawal records and complete transaction histories, including Bitcoin activity, may have been compromised.

The unauthorized request came from an email address within the domain infrastructure of a genuine government agency, with valid authentication credentials. Revolut later realized the request was fraudulent, blocked the sender, and began informing affected customers and regulators. However, the company did not disclose the identity of the agency or the exact number of customers impacted.

The incident has sparked concerns about the amount of personal data financial institutions collect from customers and the protocols in place when governments seek access to these records. The breach has highlighted the delicate balance between financial compliance requirements and customer privacy.

Critics have pointed out that the exposed information, especially when linked to cryptocurrency activity, can provide attackers with valuable insights. For Bitcoin holders, the leaked records could potentially reveal more than just financial transactions, as Bitcoin activity is publicly recorded on a blockchain.

While no customer funds were reported stolen, the compromised information poses a significant risk due to the combination of identity documents, contact details, residential addresses, and financial histories now accessible to potential attackers.

The breach also raised concerns about the security protocols in place at Revolut and other financial institutions. The fraudulent email that led to the data leak passed authentication checks, indicating that the attacker had unauthorized access to the government agency’s email infrastructure.

Revolut has taken steps to address the breach, including blocking the sender and notifying authorities. However, questions remain about the verification process for government requests and whether changes have been made to prevent similar incidents in the future.

Overall, the data breach at Revolut highlights the ongoing challenges in safeguarding customer information and the need for robust security measures in the financial industry.