Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers

0

Revolut disclosed customers’ passports, verification selfies and Bitcoin transaction histories after treating a fraudulent government request as legitimate.

Affected customers were told Friday that the disclosed information could include passport or driver’s license copies, verification selfies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, and account statements. Withdrawal records and complete transaction histories, including Bitcoin activity, may also have been released.

The request came from an unauthorized mailbox operating inside the domain infrastructure of a genuine government agency and carried valid authentication credentials.

Revolut subsequently contacted the agency, concluded the request was fraudulent, blocked the address and began notifying customers and regulators. The company has not identified the agency or disclosed how many customers were affected.

Compliance demands sharpen customer backlash

The incident has drawn scrutiny over how much information financial institutions collect from customers and the controls used when governments later seek access to those records.

Marc Zeller, founder of the Aave Chan Initiative, said the disclosure came shortly after Revolut demanded additional information from him, threatening to close his account.

“The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or ‘we will close your account in 20 days,’” Zeller said. He accused the company of doing the attackers’ work for them after the request fooled him.

The criticism cuts into a tension created by modern financial compliance. Banks and fintech firms collect extensive identity and transaction records to satisfy know-your-customer and anti-money laundering requirements. Those databases become especially sensitive when they link verified identities and residential information to cryptocurrency activity.

For Bitcoin holders, the exposed records could give an attacker far more than a financial statement. Bitcoin transactions are recorded on a public blockchain, meaning information tying a known person to specific activity can potentially help map that individual’s wider onchain footprint.

Onchain investigator ZachXBT, who publicized the incident, said the disclosure appeared limited in scale and may have targeted high-net-worth customers. Revolut has not provided a figure that would establish the scope of the incident.

No customer funds have been reported stolen, and the information described in Revolut’s notices did not include passwords, card PINs or cryptocurrency private keys.

The immediate risk instead stems from the combination of identity documents, contact information, residential addresses and financial histories now potentially available to the attacker.

A genuine government domain defeated Revolut’s checks

The method used to obtain the information leaves a separate problem for Revolut and potentially other financial institutions that received requests from the same source.

The fraudulent email passed SPF, DKIM and DMARC authentication, mechanisms designed to help verify that messages are authorized by the domain they claim to represent.

That suggests the attacker had access to an unauthorized mailbox within the government agency’s actual email infrastructure rather than simply changing the sender information on a conventional spoofed email.

Revolut said that combination led it to fulfill the request, believing it came from an authentic government authority. The firm discovered the problem after contacting the agency separately, then alerted officials to the unauthorized mailbox and blocked the sender internally.

Former Mt. Gox CEO Mark Karpelès, who circulated a copy of the notification Saturday, argued that identifying the compromised government agency could allow other banks and exchanges to determine whether they also received information demands from the same mailbox. Revolut has so far withheld the agency’s identity while it investigates.

That leaves the verification sequence as the key unresolved issue. Revolut has explained why the email looked authentic, but has yet to say whether government information requests require confirmation outside email, why it contacted the agency only after releasing customer records, or whether it has changed that process since discovering the fraud.

The post Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers appeared first on CryptoSlate.

You might also like
Leave A Reply

Your email address will not be published.