Revolut disclosed wealthy customers’ passports, verification selfies and Bitcoin transaction histories after treating a fraudulent government request as legitimate. The unauthorized request passed standard email authentication checks, including SPF, DKIM and DMARC, by operating from a genuine government agency’s actual email infrastructure. No customer funds, passwords, PINs or cryptocurrency private keys were reportedly compromised, though the combination of identity documents, addresses and financial records now potentially available to the attacker creates significant privacy risks. The company has not identified the government agency involved or disclosed how many customers were affected.
Source: Read the original article

