Bitcoin Forum
September 16, 2026, 05:10:29 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Bitcoin activity, passports exposed after Revolut data leak  (Read 591 times)
Hamza2424
Legendary
*
Offline

Activity: 1764
Merit: 1161



View Profile WWW
September 12, 2026, 08:12:41 PM
 #21

Revolut should be sued for the carelessness and they should be heavily fined. The breached their own privacy policy where I am pretty sure there is a line that says that "customer data is safe with them and won't be shared to third parties". In a normal world, the customers whose data was leaked should be compensated. Maybe that's when services like revolut will wake up and stop playing around with user data.
They mentioned that they will never sell the customer's data, but they never said they won't share user's data. And when you said this, it proves the fact that most of us think this is how every platform is. I am not saying you or many of us think they don't share our data, because we all know they do, but what it means is, we think they all violate their own terms, which can be wrong.

So they explicitly mentioned these rules, and they can give details to authorities and government when asked for legal issues. But what I did not imagine was that they did not discuss this issue on a legal level with the company. Because if someone from the authority sends me a legal notice, I would confirm it from different sources first. These days, nothing is official in email as far as I have seen.

You have to double check everything, and they sent every single detail without even flinching. It is like me asking my father or mother to send their ID cards and they send them without any question because they know me, and I usually ask them to send them, so they were sharing before this as well. Anyway, nothing new.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Livingleged
Full Member
***
Online Online

Activity: 308
Merit: 194



View Profile
September 12, 2026, 08:42:20 PM
 #22

~snip
A fake government Email has led to serious data leak from Revolut, there was no breach, they gave it out thinking it was a request from the government. Seems some scammers got some targeted data by asking nicely this time around.

This just another example that keeping your bitcoin on trusted third party doesn’t mean that your personal information is completely safe. Based on this post, the bitcoin here wasn’t hacked or stolen. The issue was that the revolut was tricked into giving sensitive customer information, including identity and bitcoin transactions history, this is one reason people don’t like registering KYC.

It’s also why privacy really matter in bitcoin, if a certain exchange, company, have your address and complete transaction history, a security failure can really expose a lot about you at once. That’s why self custody should matter. Even though the self custody doesn’t make someone automatically private, but using good privacy practice can reduce the amount of personal information connected to your bitcoin  activity and held by one company.

Sandra_hakeem
Legendary
*
Offline

Activity: 1624
Merit: 1115


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
September 12, 2026, 10:50:01 PM
 #23

Revolut should be sued for the carelessness and they should be heavily fined. The breached their own privacy policy where I am pretty sure there is a line that says that "customer data is safe with them and won't be shared to third parties". In a normal world, the customers whose data was leaked should be compensated. Maybe that's when services like revolut will wake up and stop playing around with user data.
It's that straightforward. Are they all going to pretend they don't know how the data got leaked and that people's right to privacy has been violated?

 According to the reports---  "the attacker used a legitimate government agency email domain to send fraudulent request". Am I the only person who hasn't found any sense in this at all? A legitimate government agency email, but it turns out to be a fraud? So I assume the governments are aware of this whole plot?
They just gave it away? Without any official letter from the office of the agency/government before giving such information and official request? Only from that email?. That's absolutely ridiculous from their end.
That's a new type of stupidity.
But.  I am limiting my self to as FEW And then you have people scanning their IRIS for some Shit Coins.  What has the World become!
Such a terrible abyss.

Speaking of legitimacy--- Yeah I have a LEGIT concern. Why haven't the said email been made public though?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
sunsilk
Hero Member
*****
Offline

Activity: 3766
Merit: 656



View Profile
September 12, 2026, 11:05:09 PM
 #24

Someone is probably going to be removed for his job post.

It must have really been a nice request  Tongue.

They need to expose the request itself for the public to see,  I'm not sure how it's so convincing that they just hand it out right away without any further checks or they are just some bunch of incompetent body running a centralised service.

This is another reason to stay away from this services  because  they don't  really value their customer data , all they really  care about is money and more money.
Possible. Because whoever checks it might have an idea of how phishing emails are. But this one, they fell for it and it's hard to remove that doubt that they have been convinced and have to comply to that fake government request.

While it's going to help if they will show what the actual emails is but, they might not disclose that because it seems shameful on their end.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
AVE5
Sr. Member
****
Offline

Activity: 1022
Merit: 370


Winning & Loosing is the option. Take a decision


View Profile
September 12, 2026, 11:42:18 PM
 #25

Quote
The request appeared to come from a legitimate government agency and carried credentials that passed Revolut’s checks. The company handed over customer information before separately contacting the agency and discovering that the request was fraudulent, according to notices sent to affected users.

So governments can just make demands of user's personal data's and without explanations of what essence the platforms could just release the user's data's?
I don't want to believe that because they're governments operating in the highest order that they owes us no institution or organization no excuse of their demands.
If that's so then I think it's one of the reasons the Revolut financial service platform fell into the trap of releasing user's documents without being questioned.
Most especially, the blames still goes to the organization for their ignorance of not confirming from the notable and legitimate governments official handle before releasing the information.
Definitely the company will pay for any lost at the course.
This should also teach us more lessons on the essence of making research and confirming its legitimacy before reacting to any so called official demands.

X-ray
Hero Member
*****
Offline

Activity: 3724
Merit: 574


Leading Crypto Sports Betting & Casino Platform


View Profile
September 13, 2026, 01:15:08 AM
 #26

Government need to create ZK KYC and these company only need to use ZK proof.

With how much taxes we are charged, they should at the very least do the bare minimum which is to keep our safety from being compromised like this.

These companies clearly can't do their job properly, KYC data always leaking and we are vulnerable to wrench attack, and yet when shit like this happens they don't get punished.

Needless to say, getting KYC leaked through fake government email is stupid, I bet there are more KYC leak that never get reported which might be through stupider means.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
rdluffy
Legendary
*
Online Online

Activity: 3080
Merit: 2086



View Profile WWW
September 13, 2026, 02:12:15 AM
 #27

It’s an extremely dangerous data “leak”
Selfies and photos of documents put victims in a terrible and dangerous situation

Thank goodness I don’t have a Revolut account, but they’ve been advertising a lot here in Brazil, there must be plenty of Brazilians using it
My criticism is that governments ask companies to retain the data, companies also want to hold onto that data, and the ones who get screwed are the users, that’s us  Tongue

Companies and governments demand it, but offer nothing in return if that information leaks
It’s time to rethink all of this because it’s going to get easier every day to get people’s data

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

..1win..
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████

..POKER..
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████

..GAMES..
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
SeriouslyGiveaway
Sr. Member
****
Offline

Activity: 840
Merit: 273


Bitz.io Best Bitcoin and Crypto Casino


View Profile
September 13, 2026, 03:57:17 AM
 #28

According to the reports---  "the attacker used a legitimate government agency email domain to send fraudulent request". Am I the only person who hasn't found any sense in this at all? A legitimate government agency email, but it turns out to be a fraud? So I assume the governments are aware of this whole plot?
Legitimate government agency email domain, it's written in the article on Coindesk and this following one too.
https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/

Is it mean that government agency email domain and website (?) were compromised?
I don't know.

I think about Punny code attacks and what people saw looks legitimate while it's not.
Punycode Phishing attacks - how to stay safe - Spoofed URLs and fake websites!

I notice another important piece of information from this incident.
Quote
Well-known crypto security researcher ZachXBT posted about Revolut’s email to its affected customers late on Friday. The researcher said the incident appeared to have been targeted at high net worth users.

That's quite scary and it possibly gives rich people (high net worth) to change their practice for achieving better privacy and anonymity.


█ 
███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io█ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀██
███████████████▐▌
███████████████▐▌
███▄▄████▄▄▄██▄▄
▄█████████████████████▄
████████████████████
██
█████████████████████
▀██
█████████████████████▀
▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
███████████████▄
▄███████████████████▄
▄██████████████
██████▄
▄██████████████████████
████████████████████████
███████████████████████
██████████████████████
████████████████████████
▀█████████████████████▀
███████████████████▀
███████████████▀
▀▀███████▀▀
HIGH
ODDS
 
█████████   ██

......PLAY NOW......

██   █████████
█ 
jcojci
Full Member
***
Offline

Activity: 1946
Merit: 205


Bitz.io Best Bitcoin and Crypto Casino


View Profile
September 13, 2026, 06:23:44 AM
 #29

Companies must verify the government first before they send the data even the email looks "real" from the government. They can contact by phone and that doesn't takes too long so they know that is real or fake.

And the government must clarify this because customers can lose trust to them but customers can't do anything because their data has been moves to the fake government official.

Outhue
Hero Member
*****
Offline

Activity: 1680
Merit: 697



View Profile WWW
September 13, 2026, 06:37:42 AM
 #30

The existence of AI will bring alot of problem, and it's what we are witnessing right now, but in the long run it will be for the best because many vulnerability will be exposed and they will be fixed, but there is catching up that must be done, the way AI is helping scammers work is very fast, fixing solutions should be just as fast too but that's not what's happening currently. I think this won't stop any time sooner

lovesmayfamilis
Legendary
*
Offline

Activity: 2940
Merit: 5865


🧿🌿🕊️


View Profile
September 13, 2026, 10:28:10 AM
 #31

This is a case of common negligence. It is reasonable to assume that, and it can be assumed that, whoever transmitted this confidential data is directly related to those who allegedly forwarded such a letter upon request. Everything is bought, and everything is sold. There's always someone you can buy. This appears to be an orchestrated incident, when one sends and the other passes, and they get away with it. If such stories are not isolated, then the company is obliged to review its staff and not only pay fines but also punish direct participants who are so negligent about fulfilling their duties.

Tamaperdana
Full Member
***
Offline

Activity: 910
Merit: 208



View Profile
September 13, 2026, 11:24:08 AM
 #32

Why is an actual government agency getting such easy access to private information that was entrusted to the service without the users being informed of it? Highly sensitive data like residential address and privacy documents should not be readily available on request.
This circulation of private documents also creates multiple points of breaches. When you have a 3rd, 4th and 5th party involved, it has technically already been leaked.
Yes, it's clearly incomprehensible and incomprehensible, because basically, even if the request is from the government, the service provider must first notify its customers and ask for permission. Because if it were to arbitrarily leak or share someone's personal data that easily to the government, it's clearly not good. Because basically, it's personal data, and private. But yes, maybe the service provider is trying to obey the government, and they think they are free to do so. Because basically, if it were really from the government, and not from a fraudster, I'm sure the customers wouldn't know at all. But because it was actually from a fraudster, people finally found out about this. So after I saw this, I became even more afraid to give my personal data to any company. Because the risks are like this. But yes, nowadays it's sometimes very difficult to avoid things like KYC.

Lucius
Legendary
*
Offline

Activity: 4088
Merit: 7792


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 13, 2026, 12:38:15 PM
Merited by SeriouslyGiveaway (1)
 #33

Data like personal documents after leaked will never be able to retrieved back and people in such situation will never gain their privacy back. What they can get is only some sort of money, if they are lucky enough to get it as compensation from companies.
~snip~


There is a way to protect your privacy should something like this happen - by requesting the cancellation of your old documents and the issuance of new ones. That naturally comes at a price, but it can be done. What's a little more difficult is changing your address or name, but there are people who will do that if they feel threatened.

The key thing is that you should not trust anyone when it comes to your documents, especially private companies like Revolut or any CEX. Criminals are looking for every possible way to get hold of information about people who trade or own cryptocurrencies, and that is why it is necessary to start using decentralized services that do not require KYC.

PERtua
Full Member
***
Offline

Activity: 496
Merit: 110



View Profile
September 13, 2026, 01:12:56 PM
 #34

What is most troubling about all of this is that the leaked information wasn't only KYC info. A passport home address. And a phone number together with the information from a Bitcoin transaction history is a more powerful tool in the attacker's hands than any of these information items would be individually. This data, even if it hasn't been used to affect the Bitcoin. Could make the targeted phishing. Impersonation and even physical attacks much easier. In any case. If a customer claims that they were not hacked it doesn't really affect the situation. The risk to customers is not diminished if the verification process fails and sensitive information can be accessed by unauthorized persons. One question that's more important is how many checks should have to be done before a company could release such information.

███████████    B I T L I S T        🔄 MIXERS     📈 EXCHANGES     🎰 CASINOS    ███████████
████████████████████     CATALOG CRYPTO WEBSITES #KYCFREE    ████████████████████
███████████    |   Bitcointalk Archive   |   Image Hosting   |  Currency Converter  |    ███████████
SeriouslyGiveaway
Sr. Member
****
Offline

Activity: 840
Merit: 273


Bitz.io Best Bitcoin and Crypto Casino


View Profile
September 13, 2026, 01:18:13 PM
 #35

There is a way to protect your privacy should something like this happen - by requesting the cancellation of your old documents and the issuance of new ones. That naturally comes at a price, but it can be done. What's a little more difficult is changing your address or name, but there are people who will do that if they feel threatened.
There are ways to do that but these methods are only helpful for you in your homeland. I am not quite sure that if you request a new identity card, a new passport from your government, and consequently previous one will be cancelled and become invalid, these leaked documents will still be able to use by other people.

They can do things like using such identity documents for opening and verifying accounts on centralized exchanges. You can not control that and exchanges will possibly approve those registrations and KYC with your old documents. Exception is if you already had accounts on those exchanges, and exchanges detect overlap among documents and refuse later accounts use your documents, even old version.

Quote
The key thing is that you should not trust anyone when it comes to your documents, especially private companies like Revolut or any CEX. Criminals are looking for every possible way to get hold of information about people who trade or own cryptocurrencies, and that is why it is necessary to start using decentralized services that do not require KYC.
I agree with you.

I know there is thing like Right to be forgotten, but as you said, we can not trust anyone, any entity about that. We can send a forgotten request, they approve that, but who knows what they do after sending an approval email to us.

Art. 17 GDPRRight to erasure (‘right to be forgotten’).
Right to be forgotten.

█ 
███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io█ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀██
███████████████▐▌
███████████████▐▌
███▄▄████▄▄▄██▄▄
▄█████████████████████▄
████████████████████
██
█████████████████████
▀██
█████████████████████▀
▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
███████████████▄
▄███████████████████▄
▄██████████████
██████▄
▄██████████████████████
████████████████████████
███████████████████████
██████████████████████
████████████████████████
▀█████████████████████▀
███████████████████▀
███████████████▀
▀▀███████▀▀
HIGH
ODDS
 
█████████   ██

......PLAY NOW......

██   █████████
█ 
Felicity_Tide
Sr. Member
****
Offline

Activity: 882
Merit: 385


cout << "Bitcoin";


View Profile
September 13, 2026, 08:07:09 PM
 #36

A fake government Email has led to serious data leak from Revolut, there was no breach, they gave it out thinking it was a request from the government. Seems some scammers got some targeted data by asking nicely this time around.

~snip
.

What's even more disappointing about this whole thing is that Revolut has decided to handle things privately rather than make it transparent... No communication/announcement via their official X account till this very moment. Those who asked their support X(Twitter) account whether they were affected were told to send a DM for direct assistance.

Imagine handling people's personal email address, contact, selfies, Bitcoin tx history, etc,  and then having that information exposed to attackers. Judging by the popular Malone Lam's case and other social engineering scams that we've seen, I think those information are more than enough to exploit customers, most likely through the same technique. And something I find annoying is that companies often believe they can rectify issues like this through damage control.

Faisal2202
Hero Member
*****
Offline

Activity: 2044
Merit: 611


#kycfree 🗽


View Profile WWW
September 13, 2026, 09:12:44 PM
 #37

How the scammers got the emails it not really the biggest problem here but it on how such sensitive information could be released base on a request without any form of another verification.

They should be more than just a security checks before releasing data likes passports, transactions history and even him addresses. Just a mistake can just expose information that can’t be taken back or changed.
They demanded data of high valued users. How did scammers know about them in the first place as well? Maybe they already cross referenced this all from the previous breaches, like from Trezor, etc. Then chose some names on the basis of some other metrics and then hacked the email to request the data.

But even for a second, if I imagine I am a hacker, what's the chance that after hacking the email I could get data like this? So this shows they were not hacking email for this purpose. They hacked it for other reasons. They just happened to see the exchange of data between them, and they used this opportunity quickly and got the data of many high valued customers, who have been notified by the emails as well.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
snowpega
Sr. Member
****
Offline

Activity: 1050
Merit: 485



View Profile WWW
September 13, 2026, 10:05:18 PM
 #38

They demanded data of high valued users. How did scammers know about them in the first place as well? Maybe they already cross referenced this all from the previous breaches, like from Trezor, etc. Then chose some names on the basis of some other metrics and then hacked the email to request the data.

But even for a second, if I imagine I am a hacker, what's the chance that after hacking the email I could get data like this? So this shows they were not hacking email for this purpose. They hacked it for other reasons. They just happened to see the exchange of data between them, and they used this opportunity quickly and got the data of many high valued customers, who have been notified by the emails as well.

Such incidents have become very common day by day, right?
And I really sometimes think that the way technology and the way of scamming other people are advancing day by day, where are we safe as a crypto space user? They are leaving no room for our safety. Whenever any technology gets advanced, or a new idea gets developed for crypto space user saty hacker try to crack it by finding any possible way.

The meaning of this is that not only are developers getting advancement because hackers are also becoming more advanced.
Did you notice a little guy case, who was employ in google i think (CMIIW), who stole around 4000 bitcoins by accessing hard drives? And, in this case, we have a perfect example that we are not even from reputable companies if we store our valuable data in their data centres or databases. What do you think about this?

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
████████████████████████████████████████████████████████████████████
Lock.com
 
████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 Open-code isolated Crypto Wallet   

████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
Alphakilo
Sr. Member
****
Offline

Activity: 1190
Merit: 317


⭐ Razed.com ⭐ The Best Crypto Casino


View Profile
September 13, 2026, 10:44:08 PM
 #39

A fake government Email has led to serious data leak from Revolut, there was no breach, they gave it out thinking it was a request from the government. Seems some scammers got some targeted data by asking nicely this time around.

~snip
.

What's even more disappointing about this whole thing is that Revolut has decided to handle things privately rather than make it transparent... No communication/announcement via their official X account till this very moment. Those who asked their support X(Twitter) account whether they were affected were told to send a DM for direct assistance.

Imagine handling people's personal email address, contact, selfies, Bitcoin tx history, etc,  and then having that information exposed to attackers. Judging by the popular Malone Lam's case and other social engineering scams that we've seen, I think those information are more than enough to exploit customers, most likely through the same technique. And something I find annoying is that companies often believe they can rectify issues like this through damage control.
It's always a case of taking medication after the headache has subsided. This has been happening lately under companies many of us have never heard of or have heard of but is still a new platform with customers that think they are genuine and trustworthy enough to keep their data safe.

I mean, almost same issue happened when Google leaked users data and as old as they have been in the he business they didn't see it coming, let alone newer CEX with kyc requirements and customer database that have no experience or have learnt from the experience of others about how data breach could occur and gave an already safe proof mechanism in place.

This isn't money that got stolen, but real identities of individuals that could be sold on the dark web to the highest bidder and it can't be changed or repaid or reclaimed because a persons identity is what they bear for a life time.

Checks and verification proof has to always be ensured in proper by these crypto KYC platforms to avoid such every happening, mostly when those requesting are so humble in their request or stern and with proper documentation. Still do a background check directly from the source to confirm the request always.

RAZED | 100%  
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
|
NO
KYC
██████████████████
 RAZE THE LIMITS   PLAY NOW
██████████████████
Dave1
Hero Member
*****
Offline

Activity: 2156
Merit: 645



View Profile
September 14, 2026, 01:44:07 AM
 #40

The thing is that they have plans of an IPO next year or the next, so for sure this news are going to affect them negatively,



https://www.cmcmarkets.com/en/ipo-trading/revolut-ipo

And they are a big fintech company so they have a high level of clientele. Now their data is exposed so it's going to be ugly for this wealthy people as their data in now at the mercy of the criminals.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀
 
..PLAY NOW..
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!