Revolut Discloses KYC Documents, Selfies, and Bitcoin Transaction History After Fraudulent Government Email Bypasses Verification
What Happened – Revolut unintentionally released customers’ identity documents, selfies, and full Bitcoin transaction histories to an unauthorized party after a fake government email—using a legitimate‑looking domain and valid authentication headers—passed its request‑validation checks.
Why It Matters for Trust & Control Assurance
- Demonstrates a gap in the control that authenticates and authorises external data‑request communications, a core objective of any continuous control‑assurance program.
- Highlights the need for defensible audit evidence that every KYC data release is backed by multi‑factor verification, not just domain‑based authentication.
- Directly ties to Verisq’s Access Controls capability, which provides continuous monitoring and evidence collection for request‑validation processes.
Who Is Affected – Financial services and payments platforms that collect and store regulated KYC data; fintech firms handling identity verification.
Recommended Actions
- Map the “authenticate and authorise external data requests” control to your audit‑readiness framework and collect evidence of the process.
- Implement multi‑factor verification (e.g., out‑of‑band confirmation) for any KYC data disclosure request, regardless of email authentication results.
- Log, monitor, and regularly review all KYC data release activities for anomalous patterns.
- Conduct a tabletop exercise simulating a fraudulent government request to validate response procedures.
Source: Security Affairs
Technical Notes
- Attack vector: Phishing‑style email with forged but technically valid DKIM/SPF/Dmarc headers.
- No malware or system compromise; the breach stemmed from a process failure in request authentication.
- Exposed data: full name, DOB, address, email, phone, passport/driver’s licence scans, verification selfie, account statements, IBAN, and Bitcoin transaction history.
Source: same as above