An impersonator sent requests for information about Bitcoin customers to Revolut from the legitimate email domain of a government agency.

Because the message came from an authentic government server, it passed SPF, DKIM, and DMARC without issue. To Revolut’s filters, it looked like a genuine request. And the information was handed over before the request was directly verified.

Passports. Verification selfies. Addresses. IBANs. Account statements. Bitcoin transaction histories.

Customer funds were not compromised. The data was.


There is something very important here: the technical controls didn’t fail. They worked correctly on an email that was technically authentic.

What was missing was a process control: independently verifying that the person making the request was actually who they claimed to be before handing over the information.

ZachXBT (a well-known onchain security investigator) pointed out that those affected appeared to be higher-net-worth customers. In other words, this doesn’t look like an indiscriminate breach. There seems to have been some serious targeting involved. 👀

As for AI: this attack didn’t even need it. A legitimate government mailbox was enough.

What AI changes isn’t necessarily the sophistication of the attack vector. It changes the cost of replicating it at scale.

That’s why it’s worth talking about good practices and standards such as ISO/IEC 27001 and 27002. Not because a certification makes anyone invulnerable, but because it forces organizations to ask concrete questions instead of leaving them for later or for “when there’s time.”

In this particular case, two controls could have changed the outcome: independent verification of requests from authorities, and minimizing what is actually disclosed compared with what is requested.

Security isn’t just technology.

It’s people, processes, and policies.

Follow Us in LinkedIn