Revolut duped by spoofed government email, hands over customer data including Bitcoin records
AI مارکیٹ کا خلاصہ
Revolut disclosed a data leak after acting on a spoofed government request, exposing customer identity documents and detailed Bitcoin transaction and withdrawal records. While funds and internal systems were reportedly unaffected, the breadth of KYC and onchain history heightens counterparty, privacy, and personal-safety risks (including targeted extortion), potentially chilling user activity around custodial fintech and crypto rails. The episode reinforces ongoing concerns about industry-wide data security and compliance workflows.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-0.79%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Revolut has warned a subset of customers that their personal data was disclosed after the firm acted on what it believed was a request from a government agency, according to CoinDesk.
The company said the message came from the agency's official email domain and passed domain verification checks, leading Revolut to treat it as authentic and provide information to the sender, who was later found to be an attacker.
Revolut said the exposed data set was broad. It included identity details such as name, date of birth and occupation, plus contact information including address, email and phone number. The notice also said copies of passports or driver's licenses submitted by some users, as well as selfie photos used for verification, were part of the breach.
For crypto users, the most sensitive elements involved financial and onchain activity. The leaked material included account statements containing IBANs and wallet reference numbers, withdrawal records, and full transaction histories with Bitcoin transaction details.
Revolut said facial biometric telemetry data was not affected. It added that its systems and customer funds were not compromised.
The company described the incident to overseas media as a "complex external impersonation scam," in which attackers sent fraudulent requests from legitimate government-agency domain email addresses to obtain customer information. Revolut said the number of impacted customers was "limited," that it has blocked the related email addresses, and that it has notified the impersonated institutions along with law enforcement and regulators. Revolut did not specify how many users were affected or which agency was impersonated.
Onchain investigator ZachXBT said the episode appears consistent with a targeted campaign focused on high-net-worth individuals. With detailed identity data and Bitcoin transaction histories exposed, industry participants have raised concerns about the risk of "wrench attacks," in which holders face real-world threats after their identities are linked to crypto holdings.
The incident follows a run of data-security issues across the crypto sector. Hardware wallet maker Trezor recently widened the scope of a customer data exposure tied to its customer service vendor, and social platform X has been suspected of a breach that prompted large-scale password resets.
Revolut launched the euro-pegged stablecoin EURR earlier this year and is evaluating plans for an IPO.