More

    Fake Government Requests Led Revolut to Disclose Customer KYC and Bitcoin Data


    An email address hosted on a real government domain caused Revolut to transfer customer KYC files and financial data to a fake requester. The London-based fintech confirmed the incident on September 12, stating that the fraudulent requests were processed because the emails carried valid domain authentication information and were believed to be official communications.

    Revolut said the incident affected a “very limited” number of its more than 80 million individual customers, while user systems and funds were not impacted. The company has not yet disclosed the specific number of people, the markets involved, the agency whose domain was used, or how long the incident lasted.

    How a Fake Government Request Got Through

    According to a customer notification posted on Telegram by blockchain investigator ZachXBT, at least one request came from an unauthorized email account. Still, it was sent directly through the official domain of a government agency.

    The email carried valid domain authentication information, leading Revolut to believe the request came from an authorized authority and proceed to provide the data. The company described the incident to TechCrunch as a “sophisticated external impersonation attack.”

    This was not a domain spoofing attempt using a domain name spelled similarly to the official address. Domain authentication indicates the email was sent through infrastructure permitted by the domain, but it does not confirm whether the person behind the account has authority to request data or whether the request has a valid legal basis.

    Revolut has not disclosed how the third party obtained the right to send emails through the government domain, what accompanying documents came with the request, or whether the company performed additional verification steps before responding.

    KYC Files and Bitcoin Records Were Disclosed

    According to the notification sent to customers reviewed by TechCrunch, the data provided included full names, dates of birth, home addresses, emails, phone numbers, and copies of identity documents such as passports or driver’s licenses. Verification selfies used for KYC identity checks, bank statements, IBANs, withdrawal histories, and full transaction histories may also fall within the affected scope.

    The notification shared by ZachXBT shows that this transaction history includes Bitcoin as well. Revolut also stated that facial biometric data was not affected, although the original selfie photo may have been provided.

    Revolut notification shared by ZachXBT

    Revolut notification shared by ZachXBT. Source: Telegram.

    The provided data could increase the risk of impersonation, identity theft, and targeted fraud. KYC information combined with Bitcoin transaction history could make phishing calls or messages more convincing.

    ZachXBT believes the incident was small in scale but appeared to target high-net-worth users. Revolut has not confirmed this assessment.

    Revolut Says Funds and Systems Were Unaffected

    Revolut stated that internal systems were not compromised and customer funds were not affected. Data was exfiltrated during the processing of the fake request, rather than being taken through direct access to user accounts.

    After discovering that the sender was unauthorized, Revolut blocked the email address and alerted the government agency whose domain was used. The company also contacted affected customers while notifying law enforcement, data protection authorities, and financial regulators.

    Revolut has not clarified when the request was received, when the data was transferred, or how long it took to detect the incident. Under UK GDPR, guided by the ICO, a breach likely to result in a risk must be reported to the supervisory authority within 72 hours of the organization becoming aware of it. Revolut said it has notified the relevant parties but has not specified when this was done.

    The Security Gap Beyond Revolut

    The Revolut incident shares similarities with a tactic warned about by the FBI in November 2024, in which criminals used compromised US and foreign government emails to send fake emergency data requests to businesses. The FBI noted listings selling access to government emails and fake request services on criminal forums in 2023 and 2024, with increased activity around August 2024.

    The agency recommends that businesses verify the sender’s identity, review accompanying documentation, and confirm the request through an independent channel. Revolut has not indicated whether it has changed its verification process or added approval steps for data requests following the incident.



    Source link

    Latest stories

    You might also like...