Revolut Gives Away Customer Passports, Selfies, and Transaction Histories to a Fake Government Request

Revolut Gives Away Customer Passports, Selfies, and Transaction Histories to a Fake Government Request

Revolut disclosed customers' passports, selfies, and full transaction histories to a fake government employee over email.

The email requesting the info came from a legitimate government domain, but from an unauthorized account, with valid domain authentication credentials. Because of this, Revolut believed they were sending the info to a real government agency.

Revolut later discovered it was not a legitimate government request and sent notices to its customers regarding what data might have been sent. The notice lists full name, date of birth, occupation, postal address, email address, phone number, passports, drivers licenses, facial verification selfies, account statements, account status, opening date, wallet reference number, and complete transaction histories including Bitcoin. Biometric facial telemetry data was not shared, so at least there's that.

The company was not hacked, this was a voluntary disclosure of their customers' data. Revolut has not made a public statement about this; we only know what we do from notices sent from Revolut to their customers.

Revolut says they've contacted the agency in order to validate the request and alert them to the unauthorized user, blocked the address internally, and began to apply precautionary protections to the affected accounts.

Revolut hasn't made public certain information about the case, such as the name of the agency involved, how the person got a valid mailbox on their domain, how many customers were affected, or when they got the request and when it was fulfilled.

As usual, multiple things had to go wrong for all of this to take place. The first problem is that Revolut even had so much data in the first place to give away. It's not really their fault though: so-called Know Your Customer (KYC) laws require companies like Revolut to collect sensitive data like passports, drivers licenses, and selfies in order to verify your identity.

This obviously makes any financial institution beholden to KYC laws a juicy target for hackers.

Handling sensitive user data over email is another massive issue. Email is extremely insecure by default and even assuming you do everything right, many vulnerabilities have been found in encryption software used to protect email content, and in email clients. It's not known if end-to-end encryption was used, but if it wasn't, that's even more irresponsible.

The security of the agency in question is also probably quite poor if someone was able to hack into their system and create an account. It brings the safety of your data into question, from both the companies being forced to process it to comply with laws and from the people issuing it to you in the first place.

Community Discussion