Auditen
sector watch

Revolut Data Breach Exposes Passports and Bitcoin Activity

There is a very specific brand of exhaustion you get after reading about some "sophisticated cyberattack," only to realize later that someone just didn't check who was sending them an email. It's not exciting. It's embarrassing.

Revolut confirmed they gave customer passport data and Bitcoin transaction history straight to fraudsters. This wasn't a zero-day exploit or some complex heist, and they processed fake government requests for information. If you're trying to launch in Israel, that is a clumsy way to start. The encryption didn't fail. The administrative protocol did.

The rules behind this are dry, but they matter. GDPR doesn't just say keep the data locked away; it says make sure any disclosure is lawful; when a government body asks for data, there is a standard process to verify that ask. You don't hand over a passport because someone using good letterhead asks for it. Because Revolut skipped this basic check, they didn't just suffer a breach. They actively helped distribute their own customers' private data.

You might argue social engineering is an inevitable risk in any large organization. That's the easy out. But in financial services, Know Your Customer (KYC) is usually treated with religious seriousness. The irony here is stark, and revolut applied KYC to its users but failed to apply anything like "Know Your Requestor" to the authorities asking for data.

The second-order effect will hit external auditors who recently signed off on Revolut's operational risk frameworks. If handling legal requests, a core part of any fintech compliance manual, is this porous, I have to wonder what else slipped through the cracks. I expect we'll see a sudden surge in remediation projects across the sector aimed at tightening internal verification workflows.

While one firm struggles with basic paperwork, the rest of the industry is rushing toward total automation, and openAI launched a specialized version of ChatGPT designed to handle the grunt work of junior bankers.

This creates real tension. We have firms failing at manual verification on one hand and attempting to automate professional judgment on the other; for those adopting this tool, the EU AI Act is no longer a distant theoretical concern. It is a looming filing requirement. Under the Act, high-risk systems require human oversight that actually works. Not just a rubber stamp from a senior VP who doesn't understand how the model reached its conclusion.

The risk isn't just a fine. The real danger is eroding the junior banker as a layer of defense. Junior staff are usually the ones doing tedious work like cross-referencing data and spotting anomalies. Those are the exact tasks that would have stopped a fake government request. If you remove the humans who can tolerate the boredom of verification, you increase the likelihood of this kind of administrative collapse.

Further east, the Thailand SEC is taking a more granular approach to risk, and they've proposed a daily transfer cap of 5 million Baht on stablecoins for transfers between accounts owned by the same person. That's roughly $151,000. It's a blunt instrument. Its goal is stopping people from shuffling funds around to hide their tracks or inflate volumes. It is exactly the kind of boring, specific rule that works because it limits the scale of potential loss before a human even has to look at the transaction.

It's worth comparing these two approaches: the Thai regulator’s hard cap versus the fintech industry's reliance on 'trust but verify' (where the verification part is often optional).

New Jersey saw a $16 million Ponzi scheme get charged this week. It doesn't have the systemic scale you'd find in a GDPR breach (obviously), but it reminds us that wealth management is still a magnet for people who'd rather invent things than file them.

Will the sector ever learn? Compliance isn't about overpriced AI tools or flashy consultants. It's just tedious, boring work, and you have to check that a request for a passport actually came from a government official and wasn't sent by some guy with a PDF editor and a free afternoon.

I'll be watching to see if Revolut's regulators accept 'we were tricked' as a valid defence under Article 32. History suggests they won't.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Just before Israel launch • Fintech giant Revolut confirms customer data breach by fake government requests - Haaretz Data Privacy (Google News)
  2. Thailand SEC Proposes 5 Million Baht Daily Cap on Stablecoin Transfers Under Same-Owner Rule - The Crypto Times Compliance Week (Google News)
  3. Bitcoin activity, passports exposed after Revolut falls for fake government request - CoinDesk Data Privacy (Google News)
  4. OpenAI launches ChatGPT for Financial Services to do junior banker work - Pasquale Pillitteri Compliance Week (Google News)
  5. California enacted the first U.S. laws requiring independent audits of AI systems - qz.com Compliance Week (Google News)
  6. New Jersey Man Charged in $16 Million Ponzi Scheme - Wealth Management Compliance Week (Google News)
  7. Delaware Consumer Privacy and Data-Breach Law Updates - The National Law Review InfoSec Compliance (Google News)
  8. Revolut confirms customer data breach ahead of Israel launch - Ynetnews Data Privacy (Google News)

How stories are selected and assessed