>
How to Prep in Short-Term Locations
Revolut Leak Shows the Cost of Constant ID Collection
15 US Coffee Brands to Avoid -- And 5 That Are Actually Real Coffee
Why Scammers Stay Silent for 3 Seconds When You Pick Up
Quantum computing may soon become part of the microscope itself.
Volkswagen Just Unveiled The Most Efficient EV Ever Tested
NASA Super Light Solar Sail Project Will Be 12-40 Times Lighter and Faster
Space Telescope Interferometer to Image Exoplanet Continents
Twenty-five years of "temporary": how 9/11 built a surveillance state Americans never vote
I'll Never Buy Another WALMART Battery!
Shoei GT-Air 3 Smart helmet drops with built-in AR for $1,500
AI Whistleblower Tells Tucker How AI Could Kill All Humans by 2040

Online bank Revolut has revealed that it gave out sensitive personal and financial information of an undisclosed number of its customers in response to a fake government request.
The information that was handed over to an "unauthorized third party" reportedly includes names, dates of birth, occupations, addresses, phone numbers, account numbers, transaction histories (including Bitcoin), and even copies of government-issued IDs and onboarding verification selfies.
Revolut claims that derived biometric face data was not.
The company said that the data was handed over in response to an email that came from a real government agency's domain, but was not actually sent or authorized by that agency.
The email passed several authentication checks (SPF, DKIM, and DMARC) that are designed to establish the authenticity of a message's origin and integrity, but do not verify the legitimacy of the legal request itself.
Revolut said that it complied with the request "under the reasonable belief that it was an authentic government agency request" – and only later found out that it was not.
Revolut said it later realized its mistake, blocked the email address, and reported the incident to the relevant authorities.
Revolut said that only a "limited" number of its customers were affected by the data leak, and that the company's systems were not hacked, nor was any money stolen.
The story broke on September 11 when Revolut customers started receiving an email notice about a data leak, and the news was picked up by media outlets the following day.
The reason this is a recurring problem is that companies are keeping highly sensitive information about their customers' identities, and sometimes even financial transactions, for a long time, and this data is then available to be disclosed to third parties – either in response to valid legal requests, or, as in the case of Revolut, fake ones.
One reason for this is know your customer (KYC) and anti-money laundering (AML) rules. Revolut's current UK customer privacy notice spells it out: the company generally keeps personal data of UK customers for no more than seven years after the relationship ends, and sometimes longer – for legal reasons.
This means that even if you close your account, your identity documents don't disappear.