A fake government Email has led to serious data leak from Revolut, there was no breach, they gave it out thinking it was a request from the government. Seems some scammers got some targeted data by asking nicely this time around.
How many more leaks must occur before it is acknowledged that the KYC is an "evil"? How long is the regulator prepared to disregard citizen's right to privacy for the sake of its own ambitions for power?
A fake government email slipped through security controls at digital banking giant Revolut this week, exposing residential addresses, identity documents and bitcoin transaction histories belonging to a wide group of customers.
All that remains is to provide the attackers with a "signpost" pointing to the wallets containing bitcoins, so they don't "get lost" along the way.

The request appeared to come from a legitimate government agency and carried credentials that passed Revolut’s checks. The company handed over customer information before separately contacting the agency and discovering that the request was fraudulent, according to notices sent to affected users.
Why come up with complex hacking schemes? You could just ask politely.

The files reportedly included passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements, withdrawal records and full transaction histories, including all bitcoin activity.
In short, everything is set up to make it easy to identify these
BTC-owners.
How does the regulator intend to protect these citizens (who dutifully pay their taxes) only to then force them to undergo mandatory verification regarding KYC?
Revolut has yet to disclose how many customers were affected, and did not immediately respond to a CoinDesk request for comment on the matter.
Undoubtedly, Revolut is at fault (due to insufficient data verification), but they were acting in response to an "official government request". What were they supposed to do in that situation? Refuse the "regulator"?
The root cause here lies not with Revolut specifically, but with KYC regime itself, which was imposed by the regulator.
It said in its email that customer funds remained safe and has since notified affected users and regulators and blocked the source of the request.
Client funds are safe. For now. That is, until "guests" show up with a $5 wrench.
What did the client notification look like? "Due to a data breach and for your own safety, you should change your name, appearance, and place of residence - and basically move to another country and disappear"?

The weak point was authorization. Once the request cleared Revolut’s internal checks, someone posing as a government official gained access to the same deeply personal information the bank had collected to satisfy identity and compliance requirements.
In other words, the bank did everything the regulator requires. So, who is to blame after all?