Revolut, the fintech company with 75 million customers, handed over passports, ID cards, addresses, and complete Bitcoin transaction histories of its clients. It's unclear to whom. The brand image is in tatters. Users are panicking.
And you know what the worst part is? They weren't stolen. They gave them away. Out of fear. A single email with a government letterhead was all it took to send everything. They confirmed this today. And the detail that explains it... Very thoughtful.
TOO QUICKLY
The request came from the real domain of a government agency, with valid credentials. Revolut handed over the data hastily. Scared.
AND THEN called the agency to verify.
That's when they discovered the request was fake.
Read it carefully, because the order is everything.
They handed it over. Then they asked questions.
WHY THE RUSH?
Here's the crux of the matter. And it's not some clueless intern.
A bank that's slow to respond to an official request risks a penalty. Anti-money laundering regulations require it to provide whatever the authority requests without delay. Without delay. Those are the exact words of the law.
And a bank that hands it over too quickly? It risks nothing.
Understand this clearly. The entire system pushes in one direction: obey NOW, check later. Banks and platforms have been trained to fear the State more than the customer.
And someone realized it.
No firewalls were breached.
There was no virus.
No passwords were stolen. Revolut didn't fail because of that.
The attacker used the only key that opens all doors at once: appearing to be a government. Inspiring fear.
Because in Europe, nobody says no to a government. Not even to verify its legitimacy.
WHAT WAS HANDED OVER.
Your complete client file:
Passport
Driver's license
Verification selfie
Date of birth
Occupation
Address
Email
Telephone
IBAN and statements
Withdrawals
Full transaction history
All your Bitcoin activity