HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Revolut Discloses KYC Documents, Selfies, and Bitcoin Transaction History After Fraudulent Government Email Bypasses Verification

Revolut unintentionally handed over full KYC dossiers—including identity documents, selfies, and Bitcoin transaction histories—to an unauthorized third party after a fake government email with valid domain authentication passed its checks. The incident underscores the need for stronger authentication and audit evidence around external data‑request processes for fintech firms.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Revolut Discloses KYC Documents, Selfies, and Bitcoin Transaction History After Fraudulent Government Email Bypasses Verification

What Happened – Revolut unintentionally released customers’ identity documents, selfies, and full Bitcoin transaction histories to an unauthorized party after a fake government email—using a legitimate‑looking domain and valid authentication headers—passed its request‑validation checks.

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in the control that authenticates and authorises external data‑request communications, a core objective of any continuous control‑assurance program.
  • Highlights the need for defensible audit evidence that every KYC data release is backed by multi‑factor verification, not just domain‑based authentication.
  • Directly ties to Verisq’s Access Controls capability, which provides continuous monitoring and evidence collection for request‑validation processes.

Who Is Affected – Financial services and payments platforms that collect and store regulated KYC data; fintech firms handling identity verification.

Recommended Actions

  1. Map the “authenticate and authorise external data requests” control to your audit‑readiness framework and collect evidence of the process.
  2. Implement multi‑factor verification (e.g., out‑of‑band confirmation) for any KYC data disclosure request, regardless of email authentication results.
  3. Log, monitor, and regularly review all KYC data release activities for anomalous patterns.
  4. Conduct a tabletop exercise simulating a fraudulent government request to validate response procedures.

Source: Security Affairs

Technical Notes

  • Attack vector: Phishing‑style email with forged but technically valid DKIM/SPF/Dmarc headers.
  • No malware or system compromise; the breach stemmed from a process failure in request authentication.
  • Exposed data: full name, DOB, address, email, phone, passport/driver’s licence scans, verification selfie, account statements, IBAN, and Bitcoin transaction history.

Source: same as above

📰 Original Source
https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →