Mark Karpelès on the Revolut case: they should not have sent the information

By: www.criptonoticias.com|2026/09/13 17:00:38
  • Karpelès criticizes that Revolut did not first confirm the request with the requesting agency.
  • High-profile user data was leaked to alleged bad actors.

The former CEO of the now-defunct bitcoin (BTC) exchange Mt. Gox, Mark Karpelès, lashed out at the neobank Revolut for leaking private data of its clients.

Karpelès criticized the platform for not confirming the request with the requesting agency before processing the mass delivery of confidential information.

The incident was triggered when the financial entity proceeded to deliver records after receiving an allegedly official email, which turned out to be an advanced identity theft that compromised the privacy of its clients.

According to the entrepreneur's statements, the financial institution made a "serious methodological error" by responding to the request immediately and relegating verification to a

Revolut should not have sent customer data (KYC, historical data, etc.) in response to an email just because it came from a government agency.

Mark Karpelès, former CEO of Mt. Gox.

Indeed, high-profile user data from Revolut was leaked to alleged bad actors due to this failure in prior verification protocols.

The transferred information includes personal identification data, such as full names, dates of birth, home addresses, copies of official documents with photographs, bank statements with IBAN, detailed records of withdrawals, and the complete transaction history executed on the platform, as reported by CriptoNoticias.

In addition to personal data, Revolut provided BTC transaction histories of several clients, which increases the risk of phishing attacks against the neobank's users.

In short, Revolut should not have sent customer data (KYC, historical data, etc.) in response to an email just because it came from a government agency. https://t.co/mhEqMmUZjW
--- Mark Karpelès (@MagicalTux) September 13, 2026

"Was Revolut right?"

The legal analysis presented by the former Mt. Gox executive indicates that the argument of acting under a reasonable belief lacks legal backing within the regulations of the European Union.

Karpelès questioned the neobank's stance by publicly asking: "Was Revolut right to disclose information based on an email?".

Unlike U.S. legislation---where provision 18 U.S.C. § 2702(b)(8) contemplates emergency data requests based on the good faith of the provider---the regulatory framework of the countries where Revolut operates imposes strict banking secrecy. Under Article 6.1.c of the GDPR, any data transfer requires a prior legal obligation and does not admit good faith justifications.

In Lithuania ---the country regulating Revolut--- Article 55 of the Banking Law requires written requests transmitted through previously agreed channels and sets a formal legal deadline of up to 20 days to respond.

Similarly, in France, authorities like TRACFIN channel their requests through authenticated platforms like ERMES, and the CNIL's Guide to Authorized Third Parties mandates prior verifications (such as a confirmation call).

For all these reasons, any justification for processing an unauthenticated request immediately is ruled out.

Furthermore, Karpelès emphasized that the practical guidelines from personal data protection agencies clearly specify that entities cannot validate requests based on contextual elements or the mere appearance of the sender.

In fact, the basic protocol for email requests requires direct verification contact with the public institution through independently published official communication numbers or channels.

This case highlights the advancement of social engineering and the increasingly precise tools of hackers and attackers, who have managed to bypass controls and barriers to access privileged information. Hence, the relevance of optimizing security processes through automated tools and artificial intelligence (AI), as specialists have suggested to this medium.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com