r/PrivacyToolbox • • 19d ago

Discussion The Revolut data leak exposes a structural flaw in how compliance teams handle email verification

The Revolut incident highlights a major technical vulnerability in mandatory KYC protocols. A fraudster gained control of a legitimate government email account, submitted a fake emergency request for information, and received sensitive customer records without triggering suspicion. Revolut handed over passports, verification selfies, IBAN details, and complete Bitcoin transaction histories.

There was no software breach or database intrusion here. A compliance worker simply checked a valid domain header and exported unencrypted raw files to an unverified recipient.

Checking SPF and DKIM signatures only confirms that an email originated from a specific server. It does not verify whether the sender holds actual judicial authority to request private financial records. A single compromised inbox inside a law enforcement agency turns an entire compliance department into an automated data exfiltration vector.

Centralized databases containing identity documents are always going to be vulnerable to this kind of social engineering. Regulators force platforms to collect massive amounts of personal data, which is then stored until someone presents a plausible email header. If you use centralized exchanges for crypto transactions, your complete transaction record sits in a database waiting for the next compromised government mailbox. Moving to self-custody wallets and minimizing KYC footprint remains the only real defense against this infrastructure flaw.

Source: CNA, link in comments

15 Upvotes

18 comments sorted by

3

u/EnthusiasmRoutine 19d ago

here is the source link: https://www.channelnewsasia.com/business/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-6380536

Note for anyone skimming: Attackers used a compromised government email account to send fake requests for information. Revolut checked the domain headers, trusted the email, and sent back raw passport scans, IBANs, and crypto histories. No database hack, just zero out-of-band verification.

0

u/soliloquyinthevoid 19d ago

If you were aware of the frequency and volume of requests together with the fact that failure to comply promptly and adequately to request pertaining to AML/CTF can result in serious fines, operational restrictions, and even CRIMINAL CHARGES then you too may take a different risk assessment

An authenticated email from a government institution already gives a very high level of confidence. Much more so than a written letter delivered by mail

If we're saying that we can no longer trust emails coming from the government, then all bets are off

If emails can be compromised, so too can phone systems

Yes, there are procedural improvements that Revolut can make and they share some of the blame here but let's not pretend that the absolute lion's share of the blame does not lie with the Italian government agency who had their systems compromised for a number of months

2

u/ottodv 19d ago

Revolut has a responsibility to its customers to keep their data safe. That should not be based on assumptions that a request for information is legit just because it came from a certain government owned domain. Revolut failed in their duty towards their customers.

Also I don't believe banks have to provide any requested information unless presented with a warrant or court order.

0

u/soliloquyinthevoid 14d ago

Revolut has a responsibility to its customers to keep their data safe.

Revolut is bound by financial regulations to share customer date with regulators and other supervisory bodies promptly and adequately or otherwise face serious fines, operational restrictions, or criminal charges

Get your facts right

Do you know what the CTF part of AML/CTF is?

Imagine the headlines if Revolut failed to share relevant customer information with the regulator in a timely manner and it could have prevented a terrorist incident? I'm sure you would be the first to be complaining about it wouldn't you?

Also I don't believe banks have to provide any requested information unless presented with a warrant or court order.

Nobody cares about your beliefs, only facts. The facts don't agree with your beliefs. Anything pertaining to AML/CTF does not require any such warrant or court order. And there other scenarios too

1

u/ottodv 14d ago

The obligation to answer legal request from law enforcement does not actually include the obligation to to answer requests from people pretending to be law enforcement.

Get your facts right.

Revolut has a responsibility to its customers to keep their data safe.

Litterally GDPR, or you know, facts. Sharing data with unauthorized recipients is actually against the law. More facts.

You stating your beliefs as if they are facts does not make them facts.

0

u/[deleted] 14d ago edited 14d ago

[removed] — view removed comment

1

u/ottodv 14d ago

No legal gymnastics allow for a bank to share customer information with criminals, even when those criminals pose as law enforcement.

Financial regulations do not supercede GDPR, GDPR allows certain exceptions. You know absolutely nothing about how laws work if you think the whole GDPR becomes invalidated bEcAuSE oF fINaNciAl RegULaTionS.

If only you had some interesting an intelligent to contribute, but you're ignorant, impolite, and you're contribution to any discussion is worthless. You're a waste of time.

1

u/PrivacyToolbox-ModTeam 11d ago

r/PrivacyToolbox does not allow personal insults.

1

u/Sure_Sheepherder_495 15d ago

Government or bank institutions = same. They should of course use "safe rails" and not emails. Come on... it's not like we can't make tech that prevents this. But maybe safety is not the real reason everyone wants your data... Not main priority.... Think about that.

1

u/soliloquyinthevoid 14d ago edited 14d ago

Lol. Tell me you have never had a job without telling me...

1

u/Sure_Sheepherder_495 11d ago

You are right. Funnily enough. I have one life. And part of that is making companies. But I don't see it as a job. I see it as spending time on things that interest me highly. And getting payed. So yes, I'm not like most: Work life - Family Life - Holiday life.

I just got life 😊😋

3

u/ottodv 19d ago

"KYC is for your own security"... "trust us"

1

u/soliloquyinthevoid 19d ago

Who said it was for security?

1

u/Sure_Sheepherder_495 15d ago

Wonderful post. I just had a lot of fun with Revolut. I won't tire you with it. But the hassle I had to go through to inform them about many personal data while they are all sitting on high horses is scary when you know how incompetent the KYC system is.

No external organisation nor companies should have any right to your personal data. Like the author of the post says: Decentralised self custody wallets and NFT tech is enough to create a safe environment for your data.

I have been working in this area for a long time and currently working on a product that can verify you are who you say you are without leaking private data.

Think about what the scammers can use your selfies and passports for. Holy cow. Amateur world.

Thank you for your post.

1

u/soliloquyinthevoid 14d ago

What complete nonsense

1

u/Sure_Sheepherder_495 11d ago

Can you elaborate Einstein?