Loading prices…
🩸BEARISH

Revolut hands hackers customer passports, Bitcoin histories

Pairing verified identity with Bitcoin transaction histories turns customers into mappable onchain targets, exactly the risk compliance frameworks are supposed to prevent.

Revolut disclosed customers' passports, verification selfies and Bitcoin transaction histories to an attacker who impersonated a legitimate government agency through an email that passed every standard authentication check. The disclosure was made after Revolut treated a fraudulent government information request as genuine, then contacted the agency separately and realized the request was unauthorized.

Why it matters

The fraudulent request came from an unauthorized mailbox operating inside the email infrastructure of a real government agency, not a spoofed external address. The email passed SPF, DKIM and DMARC authentication, which Revolut said led it to fulfill the request. That combination effectively turned a compliance workflow designed to protect customers into the entry point for the breach.

The exposed records pair verified identity with crypto activity, a combination compliance frameworks were built to protect. Bitcoin transactions are recorded on a public blockchain, so tying a name, address and occupation to specific BTC flows gives an attacker a starting point to map a person's wider onchain footprint. Marc Zeller, founder of the Aave Chan Initiative, was among those notified and accused Revolut of doing the attackers' work after the firm had separately demanded more personal information from him or close his account.

Market impact

No customer funds have been reported stolen. Revolut stated the disclosure did not include passwords, card PINs or cryptocurrency private keys. The immediate risk is the package of identity documents, contact data, residential addresses and financial histories now potentially in the attacker's hands. Onchain investigator ZachXBT said the breach appeared limited in scale and may have targeted high-net-worth customers. Revolut has not disclosed the agency involved, the total number of customers affected, or whether its verification process has changed since the incident.

Related tokens
$BTC

Frequently asked questions

  1. How did hackers trick Revolut into releasing customer data?

    The attackers used an unauthorized mailbox inside a real government agency's email infrastructure. The fraudulent email passed SPF, DKIM and DMARC authentication, so Revolut treated it as a legitimate government information request.

  2. What specific information was disclosed in the Revolut breach?

    Disclosed data may include passport or driver's license copies, verification selfies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, account statements, withdrawal records and complete transaction histories including Bitcoin activity.

  3. Were any customer funds stolen in the Revolut breach?

    No. Revolut stated that passwords, card PINs and cryptocurrency private keys were not part of the disclosure. The risk stems from the combination of identity documents and crypto transaction histories now potentially in the attacker's hands.

  4. Who was affected by the Revolut data breach?

    Revolut has not disclosed the agency involved, the total number of customers affected, or how the requests were screened. Onchain investigator ZachXBT said the disclosure appeared limited in scale and may have targeted high-net-worth customers.

  5. Why is exposing Bitcoin transaction histories especially risky?

    Bitcoin transactions are recorded on a public blockchain. When identity data is layered with crypto activity, attackers can map a known person to specific addresses and trace their wider onchain footprint.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →