Revolut Tricked by Fake Government Email, Leaking 680 Customers' IDs
provenauthority · x · 2026-09-18
A hacker emailed Revolut posing as a government agency and obtained passport photos, driver's licenses, selfies, addresses and full transaction histories for 680 customers — now being drip-fed onto the web in a $3M Monero ransom attempt.
The Cointelegraph piece argues this exposes a systemic flaw in KYC: storing massive troves of identity documents to satisfy compliance creates honeypots for criminals. At least 343 million Americans were affected by breaches in H1 2026 alone, on top of the earlier leak of 153M+ US/Canadian driver's licenses. The article advocates zero-knowledge verification that confirms identity without storing documents.
More from Safety
- Hackers say they took over OpenAI employee ChatGPT accounts in under 72 hours via two bugs — nptacek · 2026-09-18
- A CTF framing via /goal was all it took to bypass Claude Opus's guardrails — xeophon · 2026-09-18
- Halvar Flake: Useful AI Side Channels Face Real Information-Theoretic and Physical Limits — basedjensen · 2026-09-18
- AI safety researcher pushes back on claims that side-channel attacks make air-gapped networks insufficient — BlancheMinerva · 2026-09-18
- Geoffrey Irving: air gaps may matter someday but are laughably far from AI companies' current security — geoffreyirving · 2026-09-18
- Debate: An Exponentially Growing API-Token-Stealing Replicator Swarm May Scare More Than Weight Exfiltration — cis_female · 2026-09-18