British digital bank Revolut admitted an internal oversight on September 12, which resulted in customers' identity documents and complete Bitcoin transaction records being sent entirely to a criminal gang.

However, starting from September 13, copies of these customers' passports and driver's licenses, as well as the selfie of the hand-held ID used for KYC, were gradually posted on X and Telegram.

According to reports from CryptoTimes and FinanceFeeds, the attackers also left a line: As payment for Revolut leaking customers' data, every day more and more will be released.

Among the victims currently identified are:

  • Mark Karpelès, the former CEO of the Bitcoin exchange Mt. Gox that shut down in 2014

  • Professional tennis player Alexander Shevchenko

  • The CEO of the online encrypted casino Gamdom, Felix Römer

As for how many people were affected, Revolut only said that the number of affected customers is “very limited” so far. However, according to a (Financial Times) report, the number of victims they notified has already reached 680.

Revolut stated that the moment it discovered anything abnormal, it immediately blocked the source of the risk and promptly notified the relevant authorities and the affected customers. In the UK, the Information Commissioner's Office, the regulator for personal data, also announced on September 14 that it would begin an investigation.

◆◆◆

Revolut’s public stance is that the company’s systems were not breached and that customers’ funds were not affected. But the passport and driver’s license copies posted online—and that selfie holding the ID—have already revealed to people around the world who you are.

On-chain sleuth ZachXBT also pointed out early in the incident that once these personal data are used by bad actors, the risks would directly extend to the customers’ assets and personal safety.

You might say, “I’m not even using Revolut—what does a UK bank’s screw-up have to do with me?”

In Taiwan, in October 2022, about 23.57 million people’s household registration data were leaked as well, and they were posted on the dark web for sale. Then the following year on March 30, a man with the surname He went to the Wenshan District Household Registration Office in Taipei City to apply for a new set of national ID numbers.

But the Household Registration Office refused the application… saying the reason was that he “did not provide specific facts and evidence that his national ID number was impersonated,” which did not meet the “special circumstances” standard set by the Ministry of the Interior.

Even if your data is already sitting on the dark web, before you are truly impersonated, that is not a reason.

A man with the surname He later appealed all the way to the Taipei High Administrative Court, and only on January 15 of this year did the court finally rule in his favor in part—taking nearly three years from the leakage of personal data to the ruling.

◆◆◆

Based on my observations, what is truly worth remembering here isn’t which step in Revolut’s process went wrong… but that every item on the leaked list cannot be remedied in the same way.

At least a national ID number can be replaced by suing to get a new one, but what about that selfie you took holding up your ID to the camera—where do you apply to have it reissued? There’s no such mechanism, so once that photo gets out, it will be out forever.

How many times have you yourself handed over selfies of you holding your ID?
Feel free to share with me~

⚠️ The above content is for reference only and does not constitute any investment advice.