Revolut Tricked by Fake Government Email, Leaking 680 Customers' IDs

provenauthority · x · 2026-09-18

A hacker emailed Revolut posing as a government agency and obtained passport photos, driver's licenses, selfies, addresses and full transaction histories for 680 customers — now being drip-fed onto the web in a $3M Monero ransom attempt.

The Cointelegraph piece argues this exposes a systemic flaw in KYC: storing massive troves of identity documents to satisfy compliance creates honeypots for criminals. At least 343 million Americans were affected by breaches in H1 2026 alone, on top of the earlier leak of 153M+ US/Canadian driver's licenses. The article advocates zero-knowledge verification that confirms identity without storing documents.

Original post →

More from Safety

Safety channel →