Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request

요약:The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.

In brief

  • Revolut disclosed sensitive customer data—including passport copies, verification selfies and full Bitcoin transaction histories—after fulfilling a fraudulent request sent from a government agency's legitimate email domain.
  • A Revolut spokesperson confirmed it was “a sophisticated external impersonation scam,” said a “limited” number of customers were affected, and stated systems and funds were unaffected, but declined to give numbers or name the agency.
  • ZachXBT said the breach appeared to target high-net-worth users, raising “wrench attack” concerns amid a wave of similar leaks.

Fintech giant Revolut handed sensitive customer data, including passport copies and full Bitcoin transaction histories, to a malicious actor after falling for a fraudulent request disguised as a legitimate government inquiry.

According to a customer notification circulated by crypto investigator ZachXBT, Revolut received a request for customer information that appeared to come from a government agency, sent from an unauthorized email account using the agency's official domain.

Myriad: Bitcoin's next move? Click to make your prediction.

Because the message carried valid domain authentication credentials, Revolut fulfilled it in the belief it was genuine.

The exposed data was extensive. Per the notice, it spanned identity details such as full name, date of birth and occupation; contact information including postal address, email and phone number; and document and verification data, including a copy of the victim's passport or driver's license and the selfie provided for verification.

Most alarming for crypto holders, the financial data included account statements with IBAN and wallet reference numbers, withdrawal records and full transaction history, including Bitcoin. Revolut said no biometric facial telemetry data was involved.

A Revolut spokesperson confirmed the breach to TechCrunch, describing it as “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”

The company said a “limited” number of customers were affected, that it had blocked the email address and alerted the agency, law enforcement and regulators, and that its systems and customer funds were unaffected. Revolut declined to say how many people were hit or which agency was impersonated.

ZachXBT said the incident appeared to target high-net-worth users, a concern given the surge in violent “wrench attacks” against known crypto holders. The leak drew sharp criticism, with several users on social media arguing the episode shows know-your-customer rules have created risk without meaningful benefit.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

나스닥, 210억 달러 가치 평가받은 크라켄 모회사에 1억 달러 투자: 보고서

다음

FTX 캐롤라인 엘리슨, ‘캐롤’로 불리며 비밀리 자선단체 활동