Press Enter to search · ESC to close

Regulation

Revolut Reportedly Leaked User Data After Falling for Fake Government Request

ZachXBT warns that Revolut may have handed user identity documents and selfies to attackers who forged a government data request, with high-net-worth clients apparently targeted. The incident highlights how centralized KYC data has become a systemic security risk for crypto users.

Revolut Allegedly Handed Over User Data Following a Forged Government Request

On-chain investigator ZachXBT has issued a warning that Revolut, the UK-based digital banking and crypto platform, appears to have mistakenly treated a fraudulent government information request as legitimate and provided partial user data to the requester. The compromised material reportedly includes identity and contact information, copies of identification documents, and verification selfies, with indications that high-net-worth users were specifically targeted.

The Mechanics of a Social-Engineering Attack

If confirmed, this incident represents a classic social-engineering breach rather than a technical exploit. Attackers impersonated a government authority to trigger a data disclosure process, and the platform’s internal verification controls failed to distinguish the forged request from a genuine legal order. For crypto-native users, the leak is especially dangerous: identity documents and selfies are the raw material for SIM-swap attacks, account takeovers, and targeted phishing that can drain exchange accounts and self-custody wallets alike.

Why High-Net-Worth Crypto Users Are Prime Targets

The reported focus on wealthy clients is telling. Crypto holders with large balances are attractive to organized crime because transactions are irreversible and assets can be moved across borders within minutes. A leaked passport scan paired with a phone number and email address gives attackers everything they need to impersonate a victim to a telecom provider or a customer-support desk. The combination of KYC data and crypto exposure creates a single point of failure that no hardware wallet can fully mitigate.

Regulatory and Industry Implications

  • AML/KYC data custody is now a systemic risk. Centralized platforms hold vast honeypots of personal data. Regulators in the UK, EU, and US are likely to scrutinize how firms authenticate law-enforcement requests.
  • Legal-request verification needs hardening. Platforms should adopt cryptographic verification, callback procedures, and multi-person approval for any disclosure of customer records.
  • User liability questions will intensify. If a platform leaks data that leads to asset theft, the line between platform negligence and user responsibility will be tested in courts and by financial ombudsmen.
  • Reputational damage could accelerate self-custody adoption. Incidents like this reinforce the argument that holding identity data at a centralized intermediary is itself a risk.

Forward-Looking Perspective

The crypto industry has spent years hardening private keys and smart contracts, yet the weakest link remains operational: a forged email or a phone call. Expect pressure on banks and exchanges to publish transparency reports on government data requests, adopt zero-knowledge or selective-disclosure identity systems, and insure against data-breach liability. For users, the practical takeaway is immediate: assume that KYC data held by any platform can eventually leak, enable hardware-based two-factor authentication, use dedicated phone numbers for financial accounts, and consider separating identity exposure from asset custody. Until legal-request verification becomes as rigorous as on-chain security, social engineering will remain one of the most profitable attack vectors in crypto.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback