{
  "version": 1,
  "event_id": "evt_eb19a2cef3159ae6",
  "url": "https://xiyu.news/events/evt_eb19a2cef3159ae6/",
  "json": "https://xiyu.news/api/events/evt_eb19a2cef3159ae6.json",
  "type": "security_incident",
  "status": "developing",
  "category": "crypto",
  "title": {
    "zh": "Revolut 误信伪造政府请求，泄露护照与比特币交易数据",
    "en": "Bitcoin activity, passports exposed after Revolut falls for fake government request"
  },
  "current_state": {
    "zh": "Revolut 数据泄露事件出现赎金要求：名为“iamnotavillain”的攻击者索要300万美元门罗币并威胁出售被盗数据，但双方尚未谈判，Revolut 称未与攻击者联系或收到要求；路透社消息称约680名客户受影响。",
    "en": "A ransom demand has emerged in the Revolut data breach: attackers calling themselves \"iamnotavillain\" are demanding $3 million in Monero and threatening to sell stolen data, but no negotiations have begun and Revolut says it has had no contact or demands from the attackers; a Reuters source said about 680 customers were affected."
  },
  "first_seen_at": "2026-09-12T15:42:55.560568+00:00",
  "last_updated_at": "2026-09-17T17:11:52.568812+00:00",
  "last_material_change_at": "2026-09-17T17:11:52.568812+00:00",
  "confidence": 0.75,
  "updates_count": 3,
  "sources_count": 4,
  "entities": [
    "fake",
    "government",
    "histories",
    "leaks",
    "passports",
    "request",
    "revolut",
    "transaction"
  ],
  "identifiers": [],
  "topics": [
    "data-privacy",
    "fintech",
    "kyc",
    "monero",
    "ransomware",
    "revolut",
    "security-breach"
  ],
  "updates": [
    {
      "update_id": "upd_7611537be65e57d7",
      "event_id": "evt_eb19a2cef3159ae6",
      "occurred_at": "2026-09-12T10:11:01Z",
      "published_at": "2026-09-12T10:11:01Z",
      "first_seen_at": "2026-09-12T15:42:55.560568Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "Revolut 误信伪造政府请求，泄露护照与比特币交易数据",
      "title_en": "Bitcoin activity, passports exposed after Revolut falls for fake government request",
      "what_changed_zh": "Revolut 披露，由于收到一封发自某政府机构官方域名邮箱的伪造信息调取请求，公司向不明第三方交出了敏感客户数据，包括护照和驾照复印件、验证用自拍照、IBAN 与钱包参考号，以及完整的比特币交易记录。Revolut 发言人称这是一起“复杂的第三方冒充诈骗”，受影响客户数量“有限”，并强调系统与客户资金未受影响，但拒绝透露受影响人数以及被冒充的是哪个机构。\n\n此次泄露把真实身份与住址直接和链上交易记录关联起来，而这正是对加密货币持有者实施线下人身攻击所需的关键组合，同时也让外界更严厉地质疑金融科技公司与交易平台如何存储和对外提供 KYC 数据。由于 Revolut 正在考虑 IPO 且今年刚推出 EURR 稳定币，这起事件对这家深度涉足加密业务的大型公司带来了监管与声誉双重压力。\n\n这封诈骗邮件通过了该政府机构域名的邮件认证校验，这正是 Revolut 将其视为真实请求的原因；公司表示没有泄露生物识别人脸数据、密码、PIN 码或私钥，因此资金并未直接损失。Revolut 已封锁该邮箱地址并通知被冒充的机构、执法部门与监管机构，但未解释为何在未通过其他渠道二次确认的情况下就交出了记录。",
      "what_changed_en": "Revolut reportedly disclosed that it was tricked by a fake government information request, exposing customers' passport data and Bitcoin transaction activity to attackers.",
      "current_state_zh": "Revolut 披露，由于收到一封发自某政府机构官方域名邮箱的伪造信息调取请求，公司向不明第三方交出了敏感客户数据，包括护照和驾照复印件、验证用自拍照、IBAN 与钱包参考号，以及完整的比特币交易记录。Revolut 发言人称这是一起“复杂的第三方冒充诈骗”，受影响客户数量“有限”，并强调系统与客户资金未受影响，但拒绝透露受影响人数以及被冒充的是哪个机构。\n\n此次泄露把真实身份与住址直接和链上交易记录关联起来，而这正是对加密货币持有者实施线下人身攻击所需的关键组合，同时也让外界更严厉地质疑金融科技公司与交易平台如何存储和对外提供 KYC 数据。由于 Revolut 正在考虑 IPO 且今年刚推出 EURR 稳定币，这起事件对这家深度涉足加密业务的大型公司带来了监管与声誉双重压力。\n\n这封诈骗邮件通过了该政府机构域名的邮件认证校验，这正是 Revolut 将其视为真实请求的原因；公司表示没有泄露生物识别人脸数据、密码、PIN 码或私钥，因此资金并未直接损失。Revolut 已封锁该邮箱地址并通知被冒充的机构、执法部门与监管机构，但未解释为何在未通过其他渠道二次确认的情况下就交出了记录。",
      "current_state_en": "Revolut reportedly disclosed that it was tricked by a fake government information request, exposing customers' passport data and Bitcoin transaction activity to attackers.",
      "detailed_summary_zh": "Revolut reportedly disclosed that it was tricked by a fake government information request, exposing customers' passport data and Bitcoin transaction activity to attackers.",
      "detailed_summary_en": "Revolut reportedly disclosed that it was tricked by a fake government information request, exposing customers' passport data and Bitcoin transaction activity to attackers.",
      "background_zh": "作为提供类银行账户与加密交易服务的受监管金融科技公司，Revolut 必须依据“了解你的客户”（KYC）和反洗钱规则收集护照等身份文件，并用自拍照进行核验。这意味着单一服务商可能集中掌握大量身份文件，以及能把个人与其比特币持仓对应起来的交易历史。所谓“wrench attack”（扳手攻击），是指通过人身暴力或威胁来夺取受害者的加密资产，它绕开了密码学防护，直接针对人而非钱包，这类犯罪随着公众对“谁持有大量加密资产”的了解增加而不断上升。",
      "background_en": "As a regulated fintech offering banking-style accounts and crypto trading, Revolut is required by know-your-customer (KYC) and anti-money-laundering rules to collect identity documents such as passports, and to verify them with a selfie. That means a single provider can hold a concentrated trove of identity documents plus the transaction history that maps a person to their Bitcoin holdings. A \"wrench attack\" refers to the use of physical force or intimidation to seize a victim's crypto assets, bypassing cryptography entirely by targeting the person instead of the wallet — a crime category that has grown alongside public knowledge of who holds large crypto positions.",
      "community_discussion_zh": "链上调查员 ZachXBT 表示，此次泄露似乎针对的是高净值用户，进一步加剧了外界对“扳手攻击”的担忧；包括 Marc Zeller 在内的社交媒体批评者认为，这起事件说明 KYC 规则几乎没有带来实际好处，反而让许多用户陷入危险。",
      "community_discussion_en": "Onchain investigator ZachXBT said the breach appeared to target high-net-worth users, fueling concern about wrench attacks; critics on social media, including Marc Zeller, argued the episode shows KYC rules have produced little upside while putting many users in harm's way.",
      "market_impact_zh": "这条传导路径通过托管与身份数据而非资产供给发挥作用：泄露使 Revolut 的加密资产客户面临被针对性攻击的风险，也可能引发监管方对交易所和金融科技公司 KYC 数据处理方式的压力，并在 Revolut 可能上市前形成声誉层面的不确定性；由于资金与私钥均未受损，对比特币的供给、流动性或价格没有直接的机制性影响。",
      "market_impact_en": "The transmission path runs through custody and identity data rather than asset supply: the leak exposes Revolut's crypto-holding customers to targeting, and it could trigger regulatory pressure on KYC data handling across exchanges and fintechs, with reputational overhang for Revolut ahead of a possible listing; since no funds or private keys were compromised, there is no direct mechanical effect on Bitcoin's supply, liquidity or price.",
      "importance_score": 8.5,
      "references": [
        {
          "url": "https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/",
          "title": "Revolut confirms customer data breach through fake government requests | TechCrunch"
        },
        {
          "url": "https://decrypt.co/378114/revolut-passports-bitcoin-activity-data-breach",
          "title": "Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request - Decrypt"
        },
        {
          "url": "https://www.trmlabs.com/resources/blog/the-rise-of-wrench-attacks-and-crypto-related-violent-crime",
          "title": "The Rise of Wrench Attacks and Crypto-related Violent Crime"
        }
      ],
      "confidence": 0.75,
      "story_ids": [
        "rss:www.coindesk.com_arc_outboundfeeds_rss_:ffb0edb40b0555bf"
      ],
      "sources": [
        {
          "url": "https://www.coindesk.com/tech/2026/09/12/bitcoin-activity-passports-exposed-after-revolut-falls-for-fake-government-request",
          "label": "CoinDesk",
          "source_type": "rss",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_c72056766f20ab1d",
      "event_id": "evt_eb19a2cef3159ae6",
      "occurred_at": "2026-09-12T17:01:04Z",
      "published_at": "2026-09-12T17:01:04Z",
      "first_seen_at": "2026-09-12T18:34:38.398263Z",
      "time_precision": "published",
      "update_type": "confirmation",
      "material_change": true,
      "title_zh": "Revolut 向虚假政府请求泄露护照和比特币交易记录",
      "title_en": "Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request",
      "what_changed_zh": "Revolut 进一步确认该事件为利用合法政府机构域名邮箱实施的复杂冒充诈骗，并披露泄露数据还包括护照/驾照副本、验证自拍、联系方式、IBAN/钱包参考号、提现记录和完整比特币交易历史；受影响客户数量有限，公司已封锁该邮箱并通知该机构、执法部门和监管机构，系统与客户资金未受影响。",
      "what_changed_en": "Revolut further confirmed the incident was a sophisticated impersonation scam using a legitimate government agency domain email, and disclosed that exposed data also included passport/driver's license copies, verification selfies, contact details, IBAN/wallet reference numbers, withdrawal records and full Bitcoin transaction histories; a limited number of customers were affected, the company blocked the email address and alerted the agency, law enforcement and regulators, and said systems and customer funds were unaffected.",
      "current_state_zh": "Revolut 已确认遭遇利用合法政府机构域名邮箱发起的复杂冒充诈骗，有限数量客户的身份、验证及比特币交易数据被泄露；公司已封锁相关邮箱并通知该机构、执法部门和监管机构，称系统与客户资金未受影响，但未披露受影响人数及被冒充机构。",
      "current_state_en": "Revolut has confirmed it was hit by a sophisticated impersonation scam using a legitimate government agency domain email, exposing identity, verification and Bitcoin transaction data of a limited number of customers; it blocked the email address and alerted the agency, law enforcement and regulators, said systems and customer funds were unaffected, but did not disclose the number affected or the impersonated agency.",
      "detailed_summary_zh": "Revolut disclosed that it handed over customer passports, verification selfies, and full Bitcoin transaction histories to attackers who spoofed a legitimate government email domain, in what it called a sophisticated impersonation scam affecting a limited number of customers.",
      "detailed_summary_en": "Revolut disclosed that it handed over customer passports, verification selfies, and full Bitcoin transaction histories to attackers who spoofed a legitimate government email domain, in what it called a sophisticated impersonation scam affecting a limited number of customers.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 8.0,
      "references": [],
      "confidence": 0.96,
      "story_ids": [
        "rss:decrypt.co_feed:16161750d1130185",
        "rss:www.theblock.co_rss.xml:ca3ff9c93ca5a01e"
      ],
      "sources": [
        {
          "url": "https://decrypt.co/378114/revolut-passports-bitcoin-activity-data-breach",
          "label": "Decrypt",
          "source_type": "rss",
          "official": false
        },
        {
          "url": "https://www.theblock.co/news/business/2026-09-12-revolut-says-customer-kyc-bitcoin-transaction-data-exposed-after-fake-request-from-govt-domain-414516",
          "label": "The Block",
          "source_type": "rss",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_423c0db779856d9f",
      "event_id": "evt_eb19a2cef3159ae6",
      "occurred_at": "2026-09-17T13:10:53Z",
      "published_at": "2026-09-17T13:10:53Z",
      "first_seen_at": "2026-09-17T17:11:52.568812Z",
      "time_precision": "published",
      "update_type": "escalation",
      "material_change": true,
      "title_zh": "Revolut 遭300万美元门罗币赎金勒索，源于客户数据泄露",
      "title_en": "Revolut faces $3M ransom demand after data breach, report",
      "what_changed_zh": "攻击者“iamnotavillain”声称对Revolut数据泄露负责，索要300万美元门罗币赎金，威胁若不支付将出售被盗客户数据；谈判尚未开始，Revolut称未收到任何要求；路透社称约680名客户受影响。",
      "what_changed_en": "Attackers \"iamnotavillain\" claimed responsibility for the Revolut data breach and demanded $3 million in Monero ransom, threatening to sell stolen customer data if unpaid; negotiations have not begun, Revolut said it has received no demands; Reuters reported about 680 customers affected.",
      "current_state_zh": "Revolut 数据泄露事件出现赎金要求：名为“iamnotavillain”的攻击者索要300万美元门罗币并威胁出售被盗数据，但双方尚未谈判，Revolut 称未与攻击者联系或收到要求；路透社消息称约680名客户受影响。",
      "current_state_en": "A ransom demand has emerged in the Revolut data breach: attackers calling themselves \"iamnotavillain\" are demanding $3 million in Monero and threatening to sell stolen data, but no negotiations have begun and Revolut says it has had no contact or demands from the attackers; a Reuters source said about 680 customers were affected.",
      "detailed_summary_zh": "Revolut is facing a $3 million Monero ransom demand from attackers claiming responsibility for a customer data breach, with threats to sell stolen data if unpaid.",
      "detailed_summary_en": "Revolut is facing a $3 million Monero ransom demand from attackers claiming responsibility for a customer data breach, with threats to sell stolen data if unpaid.",
      "background_zh": "门罗币是一种2014年推出的注重隐私的加密货币，默认混淆交易细节，因此在付款方希望规避链上追踪的勒索软件和暗网市场中被广泛使用。Revolut 是一家总部位于英国的金融科技公司，为数千万用户提供银行、支付和加密货币交易服务，其在2022年也曾遭遇一次社交工程数据泄露，影响超过5万名客户。此次事件也是2025至2026年加密企业数据泄露潮的一部分，硬件钱包厂商 Trezor 的第三方邮件服务商 Brevo 被攻破，攻击者借此向约34.7万个地址发送钓鱼邮件。",
      "background_en": "Monero is a privacy-focused cryptocurrency launched in 2014 that obfuscates transaction details by default, making it widely used in ransomware and darknet markets where payers want to avoid blockchain tracing. Revolut is a UK-based fintech offering banking, payments and crypto trading to tens of millions of users, and it suffered a separate social-engineering data breach in 2022 affecting over 50,000 customers. The incident fits a broader run of 2025–2026 data leaks at crypto firms, including hardware wallet maker Trezor, whose third-party email provider Brevo was breached and used to send phishing emails to roughly 347,000 addresses.",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "传导路径主要是声誉与监管层面而非价格驱动：赎金索求本身不会推动 XMR 行情，但门罗币反复与敲诈勒索挂钩，会强化促使交易所下架隐私币的合规压力，从而影响 XMR 的流动性与可获取性。对 Revolut 而言，风险敞口来自用户信任以及监管机构对其数据处理和加密相关服务的潜在审查，情绪还会外溢至整个金融科技与加密的衔接领域。",
      "market_impact_en": "The transmission path is mainly reputational and regulatory rather than price-driven: the demand itself does not move XMR markets, but recurring association of Monero with extortion reinforces the compliance pressure that has led exchanges to delist privacy coins, which affects XMR liquidity and access. For Revolut, exposure runs through user trust and potential regulatory scrutiny of its data-handling and crypto-adjacent services, with sentiment spillover to the broader fintech–crypto interface.",
      "importance_score": 7.5,
      "references": [
        {
          "url": "https://en.wikipedia.org/wiki/Monero_(cryptocurrency)",
          "title": "Monero (cryptocurrency)"
        },
        {
          "url": "https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/",
          "title": "Revolut confirms customer data breach through fake government requests | TechCrunch"
        },
        {
          "url": "https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider",
          "title": "Security incident at Brevo, our third-party email provider | Trezor"
        }
      ],
      "confidence": 0.95,
      "story_ids": [
        "rss:protos.com_feed_:2266bb03f6c85714"
      ],
      "sources": [
        {
          "url": "https://protos.com/revolut-faces-3m-ransom-demand-after-data-breach-report/",
          "label": "Protos",
          "source_type": "rss",
          "official": false
        }
      ]
    }
  ]
}
