Fintech Revolut has confirmed that it shared sensitive information from a limited number of customers with unauthorized third parties after responding to a fraudulent legal request that appeared legitimate.
## The mistake that exposed data
The story is simpler and at the same time more worrying than it seems. We are not talking about a cyberattack on **Revolut**'s servers, the kind that makes us think of hackers in hoodies. Here the failure was more down-to-earth, more human: blind trust in an email. Someone, quite ingeniously, set up an email address within the domain of a public body. The trick was that this email passed all technical authenticity checks, as if the government itself were knocking at the door. **Revolut**, believing it was a legitimate legal request, forwarded the required information. The problem is that by the time they realized the deception, it was too late.
## What information was shared?
The list of data that could have been exposed is long and worrying. We are talking about details that go far beyond a simple name. Full names, dates of birth, occupations, postal addresses, emails and phone numbers could have been shared. But the matter gets more serious: copies of passports or driving licences, identity verification selfies, bank details such as the IBAN, account status and opening date, and even wallet references. And yes, also statements, withdrawal records and complete transaction history, including **Bitcoin** transactions. Although the company assures that no passwords, PINs or funds were shared, the combination of identity documents with cryptocurrency transaction history opens the door to linking real identities with on-chain activities.
## A flaw in the procedure
What is most striking about this incident is that it highlights a weakness in the standard procedures of financial institutions. The customer identification process, known as **KYC** (Know Your Customer), is rigorous to protect users. However, verifying the identity of the person requesting that information, when done through electronic means that appear legitimate, seems to have a blind spot. **Revolut** has stated that it is a "sophisticated external impersonation scam" and has taken measures, such as blocking the email address, alerting the authorities and applying protections to the affected accounts. Even so, the possibility that the data has fallen into the wrong hands is a reality that cannot be ignored.
Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication.
Read the full discussion (2 replies).
According to a forum, Ozempic alone cannot cure morbid obesity, and when treatment ceases, the weight rebounds; public prescription requires strict criteria.
The Ceuta Government Delegate’s reference to CNI reports in sealed envelopes sparked outrage, but the 1969 Decree already allowed for closed channels and secure transmission methods.