Revolut exposed customer passports and full transaction data to a spoofed government request
gnukeith · x · 2026-09-12
What happened
- Revolut disclosed it complied with a fraudulent government request: attackers used a spoofed official email with valid credentials, and the company handed over sensitive customer data.
What leaked
- Passports/driving licences, verification selfies, names, DOBs, occupations, home addresses, emails, phone numbers, IBANs, account statements, and full transaction histories including Bitcoin activity.
Status
- No funds lost and systems weren't hacked, per Revolut; affected users and regulators were notified.
- Quoting gnukeith's warning about surveillance-state data retention: forced KYC and long-term data storage make such social-engineering breaches catastrophic.
More from Safety
- Researcher decompiles 494 App Store wallet apps, finds 45 with red flags — RSync25 · 2026-09-12
- Claude-Red: Open-Source Red-Team Skill Library for Claude Hits 3.3k Stars — SnailSploit · 2026-09-12
- Bill to ban "artificial superintelligence" mocked as policy cosplay with no workable definition — johnseach · 2026-09-12
- Deepfake ads impersonate influencers to hawk GLP-1 drugs, eroding creator trust — nordicinst · 2026-09-12
- The paranoid style in AI safety: an adversarial frame can create the adversary you fear — sebkrier · 2026-09-12
- rao2z: If Your Agents Escape the Sandbox, Your Sandbox Is Bad—Not the AI Conniving — rao2z · 2026-09-12