Key Takeaways
- Revolut leaked user data to hackers posing as a government agency, exposing clients to identity theft risks.
- The leaked data included names, addresses, and ID images, which ZachXBT warned targeted high-net-worth users.
- This breach fuels global backlash against mandatory KYC rules as physical attacks on holders escalate.
Revolut Leaks Customer Information To Unidentified Threat Actors
Revolut, a UK-based neobank, has recently found itself in hot water after inadvertently sharing sensitive customer information with unidentified threat actors.
An email sent to customers revealed that Revolut, with a massive user base exceeding 70 million globally, unknowingly disclosed personally identifiable information (PII) to individuals posing as a government agency. This data was provided in response to a request-for-information email that originated from an unauthorized domain.
“The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request,” the company explained.
While the institution allegedly involved was not disclosed, Revolut did confirm that the leaked information included vital details such as names, dates of birth, occupations, addresses, email addresses, and phone numbers, posing a significant risk to the affected customers’ personal security.
Furthermore, the leaked data also included sensitive documents and verification details like passport and driver’s license images with facial verification pictures, potentially exposing customers to identity theft.
Marc Zeller, founder of the now-defunct Aave Chan Initiative, was among the customers impacted by this breach.
“Woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way,” Zeller shared on social media.
Crypto analyst ZachXBT highlighted that although the incident may have been limited in scale, it appears to have targeted high-net-worth users, increasing the vulnerability of those affected.
This breach adds to the growing global scrutiny surrounding know-your-customer (KYC) regulations, as various institutions and crypto companies have fallen victim to data leaks, putting users’ personal security at risk amidst a surge in physical attacks on holders.
