Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers

摘要:Revolut said it disclosed sensitive records of its users after a fraudulent government request passed its authentication checks.

Revolut disclosed customers passports, verification selfies and Bitcoin transaction histories after treating a fraudulent government request as legitimate.

Related Asset Bitcoin #1 BTC · $77,463.43 24-hour change: down 1.55% 24H Down 1.55% 7D Down 2.90% 30D Up 21.71%

Affected customers were told Friday that the disclosed information could include passport or drivers license copies, verification selfies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, and account statements. Withdrawal records and complete transaction histories, including Bitcoin activity, may also have been released.

The request came from an unauthorized mailbox operating inside the domain infrastructure of a genuine government agency and carried valid authentication credentials.

Related Company Revolut Banking and payments app

Revolut subsequently contacted the agency, concluded the request was fraudulent, blocked the address and began notifying customers and regulators. The company has not identified the agency or disclosed how many customers were affected.

Compliance demands sharpen customer backlash

The incident has drawn scrutiny over how much information financial institutions collect from customers and the controls used when governments later seek access to those records.

Marc Zeller, founder of the Aave Chan Initiative, said the disclosure came shortly after Revolut demanded additional information from him, threatening to close his account.

“The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or ‘we will close your account in 20 days,’” Zeller said. He accused the company of doing the attackers work for them after the request fooled him.

The criticism cuts into a tension created by modern financial compliance. Banks and fintech firms collect extensive identity and transaction records to satisfy know-your-customer and anti-money laundering requirements. Those databases become especially sensitive when they link verified identities and residential information to cryptocurrency activity.

For Bitcoin holders, the exposed records could give an attacker far more than a financial statement. Bitcoin transactions are recorded on a public blockchain, meaning information tying a known person to specific activity can potentially help map that individuals wider onchain footprint.

Onchain investigator ZachXBT, who publicized the incident, said the disclosure appeared limited in scale and may have targeted high-net-worth customers. Revolut has not provided a figure that would establish the scope of the incident.

No customer funds have been reported stolen, and the information described in Revoluts notices did not include passwords, card PINs or cryptocurrency private keys.

The immediate risk instead stems from the combination of identity documents, contact information, residential addresses and financial histories now potentially available to the attacker.

A genuine government domain defeated Revoluts checks

The method used to obtain the information leaves a separate problem for Revolut and potentially other financial institutions that received requests from the same source.

The fraudulent email passed SPF, DKIM and DMARC authentication, mechanisms designed to help verify that messages are authorized by the domain they claim to represent.

That suggests the attacker had access to an unauthorized mailbox within the government agencys actual email infrastructure rather than simply changing the sender information on a conventional spoofed email.

Revolut said that combination led it to fulfill the request, believing it came from an authentic government authority. The firm discovered the problem after contacting the agency separately, then alerted officials to the unauthorized mailbox and blocked the sender internally.

Former Mt. Gox CEO Mark Karpelès, who circulated a copy of the notification Saturday, argued that identifying the compromised government agency could allow other banks and exchanges to determine whether they also received information demands from the same mailbox. Revolut has so far withheld the agencys identity while it investigates.

That leaves the verification sequence as the key unresolved issue. Revolut has explained why the email looked authentic, but has yet to say whether government information requests require confirmation outside email, why it contacted the agency only after releasing customer records, or whether it has changed that process since discovering the fraud.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

FTX元幹部キャロライン・エリソン氏、改名し慈善団体勤務

下一篇

Nvidia 拟投 100 亿美元助推 Anthropic IPO 超越 SpaceX