Revolut Just Proved KYC Is DANGEROUS
Coin Bureau
30,363 views • yesterday Save 8 min 4 min read
Video Summary
A sophisticated attack exploited an Italian government email account to trick Revolut into handing over sensitive personal data for approximately 680 customers. The breach involved passport scans, selfies, addresses, and Bitcoin transaction histories, all obtained through what appeared to be official police requests sent over Italy's certified email system. This incident highlights a critical vulnerability in financial institutions' compliance processes, where the imperative for speed in responding to state requests can be exploited.
The attack targeted individuals identified as wealthy in crypto, with their on-chain activity first pinpointed before fraudulent requests were made to attach personal identities. Victims, including prominent figures like Mark Karpelis and Felix Romer, faced subsequent extortion attempts, with some discovering the breach through criminals before official notification. This event underscores a broader trend of increasing physical threats against crypto holders, raising serious questions about the efficacy and security of current Know Your Customer (KYC) regulations, which mandate extensive data retention and may inadvertently increase user risk.
Short Highlights
- Revolut Data Breach: A criminal gained access to an Italian government email account and sent fraudulent police requests, leading Revolut to disclose sensitive personal data of around 680 customers.
- Data Compromised: The leaked information included passport scans, onboarding selfies, home addresses, bank statements, and full Bitcoin transaction histories.
- Exploitation Method: The attacker used an Italian government email address on the PEC system, making the requests appear legitimate, and Revolut's compliance desk coached the attacker on fixing improperly formatted requests.
- Targeted Individuals: Victims were identified through on-chain activity, with their crypto wallets first located before fraudulent requests were submitted to obtain their personal details.
- Victim Impact: Some victims, like Mark Karpelis and Felix Romer, faced extortion attempts after the data leak, with one victim receiving blackmail messages weeks before Revolut's notification.
- Regulatory Concerns: The incident raises questions about EU regulations that mandate extensive data retention (up to 10 years), potentially increasing user risk and conflicting with privacy principles like GDPR.
- Broader Trend: This breach follows similar incidents involving Ledger and Coinbase, highlighting a pattern of customer data exposure in the crypto industry and a rise in physical threats against crypto holders.
Key Details
Sophisticated Attack on Revolut [0:00]
- Revolut experienced a significant data breach, not due to malware or hacking, but through a sophisticated social engineering attack.
- A criminal gained control of an Italian government email account to send seemingly lawful police requests.
- Revolut's compliance desk responded to these requests over six months, inadvertently handing over sensitive customer data.
"What actually happened was much more sophisticated, and, for those who value privacy, much more concerning."
Compromised Customer Data [0:41]
- The leaked data included passport scans, onboarding selfies, home addresses, bank statements, and complete Bitcoin transaction histories.
- Approximately 680 individuals, specifically chosen for being visibly wealthy in crypto, were affected.
- The breach exposed personal information far beyond basic privacy, putting individuals at direct physical risk.
"It's a document that says, here is a named human being, here is a recent photograph of their face, here is the door that they walk through at night, and here is how much Bitcoin they control."
Exploitation of Compliance Desks [1:11]
- Regulated financial institutions in Europe have lawful request desks designed to comply quickly with state orders.
- Hesitation or stalling can be treated as obstruction by regulators, creating a vulnerability that attackers can exploit.
- The attacker used an Italian government email on the Posta Elettronica Certificata (PEC) system, making the requests appear legitimate.
"The entire thing is engineered around one instruction, which is to say yes to the state, quickly, without tipping off the customer."
Victim Impact and Extortion [3:35]
- Targets were identified on-chain first, with their crypto wallets pinpointed before fraudulent requests were submitted to obtain their personal details.
- Mark Karpelis, CEO of Mt. Gox, received his notification and feared for his family's safety, calling the breach "very, very damaging."
- Felix Romer, founder of GamDom, received blackmail messages dated weeks before Revolut's notification, indicating victims were contacted by criminals first.
"This is very, very damaging, because I do believe a lot of Revolut customers are more likely to be privacy sensitive."
Regulatory Failures and Future Risks [8:11]
- EU regulations like AML require extensive data retention (minimum 5 years, extendable to 10), creating large, vulnerable data stores.
- These regulations can conflict with privacy laws like GDPR, which mandates data minimization.
- The incident highlights that current systems may not adequately protect customer data, and alternative technologies like zero-knowledge tools could offer better solutions.
"If this story proves anything, it's that you can't rely on the institutions involved to warn you before the damage is done."