{"id":18729,"date":"2026-09-14T07:59:03","date_gmt":"2026-09-14T14:59:03","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=18729"},"modified":"2026-09-14T08:00:53","modified_gmt":"2026-09-14T15:00:53","slug":"revolut-leak-shows-the-cost-of-constant-id-collection","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/09\/14\/revolut-leak-shows-the-cost-of-constant-id-collection\/","title":{"rendered":"Revolut Leak Shows the Cost of Constant ID Collection"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">And the problem with all the KYC\/AML tracking and reporting, age verification&#8230; is that these corporations and the government can&#8217;t keep your data safe. On the positive, you&#8217;ll probably be able to keep your credit locked and credit monitoring service for free as paid for by the last one to fail their OPSEC. AT&amp;T is paying for my current 3 year plan and might have been the one that paid for the last one too, stemming from their dabbling with overseas customer service&#8230;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/reclaimthenet.org\/revolut-leak-shows-the-cost-of-constant-id-collection\" target=\"_blank\" rel=\"noopener\">https:\/\/reclaimthenet.org\/revolut-leak-shows-the-cost-of-constant-id-collection<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_8b094b45-80dc-42cc-be63-f9ac70715db9\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">Revolut\u2019s mistake is the news, but the bigger problem is the growing number of companies being encouraged or required to keep copies of our most sensitive identity documents.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/09\/image-15-1024x576.png\" alt=\"\" class=\"wp-image-18730\" srcset=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/09\/image-15-1024x576.png 1024w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/09\/image-15-300x169.png 300w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/09\/image-15-768x432.png 768w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/09\/image-15-1536x864.png 1536w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/09\/image-15.png 2000w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">By Ken Macon<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Online bank Revolut has revealed that it gave out sensitive personal and financial information of an undisclosed number of its customers in response to a fake government request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The information that was handed over to an \u201cunauthorized third party\u201d reportedly includes names, dates of birth, occupations, addresses, phone numbers, account numbers, transaction histories (including Bitcoin), and even copies of government-issued IDs and onboarding verification selfies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Revolut claims that derived biometric face data was not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The company said that the data was handed over in response to an email that came from a real government agency\u2019s domain, but was not actually sent or authorized by that agency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The email passed several authentication checks (SPF, DKIM, and DMARC) that are designed to establish the authenticity of a message\u2019s origin and integrity, but do not verify the legitimacy of the legal request itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Revolut said that it complied with the request \u201cunder the reasonable belief that it was an authentic government agency request\u201d \u2013 and only later found out that it was not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Revolut said it later realized its mistake, blocked the email address, and reported the incident to the relevant authorities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Revolut said that only a \u201climited\u201d number of its customers were affected by the data leak, and that the company\u2019s systems were not hacked, nor was any money stolen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The story broke on September 11 when Revolut customers started receiving an email notice about a data leak, and the news was picked up by media outlets the following day.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/09\/KUHJrRG0g2rC.jpg\" alt=\"Revolut notice explaining customer identity and financial data was shared after an unauthorized government email request.\" style=\"width:444px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The reason this is a recurring problem is that companies are keeping highly sensitive information about their customers\u2019 identities, and sometimes even financial transactions, for a long time, and this data is then available to be disclosed to third parties \u2013 either in response to valid legal requests, or, as in the case of Revolut, fake ones.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One reason for this is know your customer (KYC) and anti-money laundering (AML) rules. Revolut\u2019s current UK customer privacy notice spells it out: the company generally keeps personal data of UK customers for no more than seven years after the relationship ends, and sometimes longer \u2013 for legal reasons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that even if you close your account, your identity documents don\u2019t disappear.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And while the incident with Revolut happened in the financial sector, it\u2019s by no means the only one that requires customers to hand over sensitive identity information. Discord, a popular chat service, <a href=\"https:\/\/reclaimthenet.org\/discord-support-breach-exposes-over-70000-government-ids\">said in an October 9, 2025 security update<\/a> that government ID photos of approximately 70,000 users may have been exposed after a third-party customer service provider got hacked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This was not a financial service, nor the same type of attack. But the result was similar \u2013 because the underlying business process was the same: requiring and storing sensitive identity documents. In the case of Discord, these were used to review age-related appeals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s hard to do anything about a copy of your old passport, or a photo of your face, or a record of your past transactions. These can be used to identify and profile you, and can be used to carry out targeted fraud. And this can happen even if the initial disclosure didn\u2019t result in financial loss.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The more companies are forced to collect and store such information, and the more of it they have, the more opportunities there are for this data to be leaked, either by the company itself or a third party it works with. That&#8217;s what makes governments&#8217; push for more ID checks just to access ordinary parts of life so reckless.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>And the problem with all the KYC\/AML tracking and reporting, age verification&#8230; is that these corporations and the government can&#8217;t keep your data safe. On the positive, you&#8217;ll probably be able to keep your credit locked and credit monitoring service for free as paid for by the last one to fail their OPSEC. AT&amp;T is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-18729","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=18729"}],"version-history":[{"count":4,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18729\/revisions"}],"predecessor-version":[{"id":18734,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18729\/revisions\/18734"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=18729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=18729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=18729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}