Fake government request exposes Revolut’s customer data and Bitcoin histories

fiverr
Coinmama


In a surprising turn of events, a fake government request passed digital banking giant Revolut’s security checks. This caused the company to unknowingly share sensitive customer data, including IDs, addresses, and Bitcoin [BTC] transaction histories.

Revolut later discovered the request was fraudulent, and hence, they blocked the attacker and notified affected customers and regulators.

How did Revolut fall prey to a fake government request?

In this phishing attack, the attacker appears to have tricked Revolut’s internal process for responding to government information requests.

Someone sent Revolut a request that looked as though it came from a real government authority. Because the email appeared legitimate and its technical authentication credentials were valid, Revolut’s security checks apparently treated the request as genuine.

coinbase

Revolut then provided customer information to the person behind the fraudulent request.

According to Revolut,

The request originated from an unauthorized email account created directly within an official government authority’s domain infrastructure.

The digital banking giant added,

The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request.

Impact of the phishing attack

This in turn resulted in sensitive KYC data – including names, addresses, contact details, IDs, and verification selfies – possibly being exposed.

The exposed data may have also included IBANs, account statements, withdrawal records, and full transaction histories, including Bitcoin activity.

Needless to say, if not addressed, this could allow attackers to link a real person’s identity, home address, and contact details to their crypto holdings and transactions.

This is especially concerning because Bitcoin transactions are public, but wallet addresses are normally not directly linked to real identities.

ZachXBT suggested the breach may have targeted high-net-worth customers, although Revolut has not confirmed the exact number or profile of those affected.

While the incident is likely limited in size, it seems to have been targeted at high-net-worth users.

The safety net

Hence, to avoid this, zero-knowledge proofs (ZKPs) are useful. They allow someone to prove they meet a requirement—such as passing identity verification—without revealing their full passport, address, or other personal data.

This supports a data-minimization approach, where institutions collect and reveal only what is necessary, reducing the damage from future breaches.

Sadly, all of this happened after the OCC granted Revolut conditional approval to establish a U.S. national bank, but it still needs to meet requirements and secure FDIC and Federal Reserve approvals to go ahead.


Final Summary

  • The attacker tricked Revolut’s internal process for responding to government information requests.
  • Though the incident looks limited in size, it seems to have been targeted at high-net-worth users.



Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*