Financial service Revolut disclosed personal data of customers to a scammer who used a legitimate email domain of a government agency to send fraudulent requests.
The requests passed the company's authentication checks. Later, it was discovered that they were not genuine.
What was exposed
The disclosed information included:
- copies of passports and driver's licenses;
- selfies for identity verification;
- full names, dates of birth, professions;
- mailing and email addresses, phone numbers;
- account statements, IBAN numbers and wallet addresses;
- records of fund withdrawals;
- complete transaction history, including operations with bitcoin.
The company confirmed that biometric data was not compromised, and customer funds and systems were not affected.
Why the scheme worked
Key detail: the attacker did not breach the infrastructure. He exploited an unauthorized account on a legitimate government domain.
To an employee processing the request, the email appeared authentic — the sender's address genuinely belonged to a real organization. Standard domain verification does not detect such forgery.
Targeting wealthy clients
The company contacted affected customers directly but did not disclose their number, country, or which agency was impersonated.
Former Mt. Gox manager Mark Karpelès reported being among those affected. Blockchain researcher ZachXBT noted that the attack appeared to target wealthy users.
This is particularly concerning given the rise in physical attacks on known cryptocurrency holders.
Debate over identification procedures
The incident sparked criticism of mandatory customer identification requirements. Users argued that collecting personal data creates risk without proportionate protection.
This argument has practical merit: the more documents a service stores, the more valuable its database becomes to criminals.
Not an isolated case
The breach occurred amid a series of similar incidents:
- hardware wallet maker Trezor reported a logistics partner breach affecting approximately 67,000 US customers;
- the same company disclosed that attackers sent phishing emails from its legitimate domain after compromising a third-party email provider;
- wallet SafePal reported a vulnerability in its order tracking system that exposed data of approximately 39,798 customers.
The takeaway
The pattern is clear: attacks target not the core infrastructure but trusted channels — government domains, email providers, logistics partners.
For users, the practical lesson: an email from a correct address of a real organization is not a guarantee of authenticity. For any personal data requests, verify information through official contacts you find independently.
The breach occurred as the company pursues a national bank license in the US and considers going public. The service has 80 million customers worldwide.