Revolut confirmed that sensitive customer data was sent to an unauthorized third party after they received what looked like a legitimate government request. The scary part? The request apparently came from an email account using an actual government agency domain, so Revolut believed it was real.
According to notices sent to affected users, the exposed data may include names, addresses, passports/IDs, verification selfies, IBANs, withdrawal records and even full Bitcoin transaction histories. Revolut says its systems and customer funds weren't compromised.
So basically… attackers didn't need to hack Revolut. They just convinced Revolut to hand the data over.
Kinda terrifying when companies collect massive amounts of KYC data "for your security" and one convincing government request can potentially expose the whole package.
Privacy isn't paranoia when your passport, home address and financial history are sitting in the same database.
Source: r/PrivacySoftwares · by /u/No_Jello4009