Crypto Prices

Revolut’s Recent Data Breach Exposes Customer Bitcoin Transactions After Deceptive Government Request

56 minutes ago
2 mins read
1 views

Incident Overview

In a troubling incident, Revolut has inadvertently revealed sensitive customer information, including Bitcoin transaction records and identity details, due to a fraudulent request that was disguised as communication from a government agency. The request originated from a fraudulent email using the domain of a legitimate government entity, which successfully passed Revolut’s domain authentication checks. This led the company to believe that the request was valid, resulting in the release of the information.

Details of the Breach

The details surrounding this breach were shared on Telegram by ZachXBT, an on-chain investigator, although the specific agency involved was not disclosed. As per the alert received by several customers on September 11, the disclosure included personal information such as:

  • Full names
  • Birthdates
  • Occupations
  • Contact information (addresses, email IDs, phone numbers)

The breach not only encompassed personal identities but also extended to copies of identity documents such as passports and driver’s licenses, along with selfies used for customer verification. Account statements were also included in the data leak, revealing information like IBANs, account statuses, opening dates, and crucially, Bitcoin wallet reference numbers and transaction histories.

Company Response

Revolut clarified that there is no evidence suggesting that a hacker breached their systems or accessed customer accounts directly; rather, the information was disclosed in response to a seemingly legitimate request. Nevertheless, the notice provided less clarity on the extent of the breach, with ZachXBT indicating it may have primarily affected high-net-worth individuals, although Revolut has not confirmed this assertion.

Regulatory Implications

As of August, Revolut reported having over 80 million users, but it’s important to note that this figure does not equate to the number of customers impacted by the data exposure. The UK Information Commissioner’s Office has flagged the risks associated with personal data breaches, including identity theft and financial fraud. However, the guidance does not confirm whether any customers have suffered negative outcomes as a result of this incident.

Potential Risks

For customers whose identities were fully compromised, the fraudulent request could provide a comprehensive view of their financial activities, raising alarm about the potential misuse of the exposed data. Unlike other disclosures, Revolut’s notice does not explicitly state that sensitive information like wallet private keys or account passwords were given to the unauthorized party.

Regulatory Compliance

Under current regulatory guidelines, if companies suffer a significant data breach, they are often required to report it to authorities within 72 hours and inform affected individuals promptly. It remains unclear whether Revolut has followed through with these necessary steps following the incident.

Future Developments

This development occurs at a time when Revolut is advancing its financial services, including the recent introduction of a euro-backed stablecoin for select customers across Europe. Meanwhile, the company is making strides toward establishing a presence in the U.S. banking sector, having received conditional approval for a bank in Stamford, Connecticut, with plans for operations to launch by 2027, contingent upon fulfilling necessary regulatory conditions.

Customer Advisory

Customers are encouraged to remain vigilant and verify the legitimacy of communications they receive, particularly concerning sensitive information requests, a stance reiterated by Revolut in their security guidelines. As of now, the repercussions of this breach and its broader impacts on Revolut’s operations are still unfolding.

Popular