Loading prices…
🩸BEARISH

Revolut Reports KYC Breach After Spoofed Government Email

Fraudulent record requests from a spoofed government email domain extracted KYC docs, IBANs and full Bitcoin transaction histories, a counterparty failure landing mid-US bank charter push.

Revolut disclosed sensitive customer KYC and transaction data to an unauthorized third party that submitted fraudulent record requests from a legitimate government agency email domain, the company told TechCrunch and The Block over the weekend. Exposed data may include names, dates of birth, postal and email addresses, phone numbers, identity documents, verification selfies, account statements, IBANs and full transaction histories including Bitcoin trades. Revolut described the attack as a "sophisticated external impersonation scam," said customer funds and core systems were unaffected, and declined to disclose how many users were hit or which government domain was used.

Why it matters

The breach lands at the most painful layer of a fintech's compliance stack: not the ledger, but the documents that prove who a customer is. Onchain investigator ZachXBT noted that the targeting pattern suggests high-net-worth users, raising the prospect that stolen selfies, ID documents and full transaction histories could fuel follow-on social-engineering or account-takeover attempts against Revolut customers. The company has notified data protection authorities, law enforcement and the relevant government agency whose domain was spoofed, but the attack vector itself, a trusted counterparty domain exploited via fraudulent requests, mirrors a separate incident this week in which attackers abused a third-party email provider tied to Trezor.

Market impact

Revolut is in the middle of a multi-pronged US and EU push that puts the breach under unusually bright regulatory scrutiny. The British fintech received conditional approval from the Office of the Comptroller of the Currency earlier this month to establish a national bank, with plans to offer traditional banking alongside stablecoin services, and is rolling out its euro-backed EURR stablecoin across the EEA. A counterparty-verification failure involving full KYC and Bitcoin transaction histories will likely surface in every US bank-charter examiner conversation about Revolut's onboarding controls.

Related tokens
$BTC

Frequently asked questions

  1. What customer data did Revolut expose in the breach?

    The breach may have exposed names, dates of birth, postal and email addresses, phone numbers, identity documents including passports and driver's licenses, verification selfies, account statements, IBANs and full transaction histories including Bitcoin trades.

  2. Were Revolut customer funds affected by the breach?

    No. Revolut said customer funds and core systems were unaffected. The company described the incident as a 'sophisticated external impersonation scam' and said it blocked the email address after identifying it.

  3. How did the attackers access Revolut customer records?

    An unauthorized third party submitted fraudulent record requests from a legitimate government agency email domain. Revolut disclosed the sensitive information in response, then blocked the email address after identifying the impersonation.

  4. How many Revolut customers were affected by the breach?

    Revolut declined to disclose the number, saying only that a limited number of customers were affected. Some began receiving notification emails on Friday, and former Mt. Gox CEO Mark Karpelès said he was among them.

  5. How does the Revolut breach compare to other recent crypto fintech incidents?

    Revolut joins a growing list, including Trezor's roughly 67,000-customer ShipMonk breach and SafePal's roughly 39,798-customer order-tracking leak. Trezor also disclosed a separate spoofed-domain phishing incident this week that mirrors Revolut's attack vector.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 44m ago
Open original →