Lyudmyla Kozlovska's avatar
Lyudmyla Kozlovska
lyuda_ODF@BitcoinNostr.com
npub13ajk...2yd9
President of the Open Dialogue Foundation, founder of BTC Coalition in the EU Support our advocacy for #freedomtech : donate@bps.odfoundation.eu
Important update on Revolut, and why this concerns anyone here whose data sits with a KYC'd service, exchange or fiat on-ramp: (1) According to the group now extorting #Revolut, and the Duel team in contact with them, the attackers took over Italian government and law enforcement mailboxes with an infostealer, sent Revolut Bank UAB in Lithuania a forged European Investigation Order in the name of the Italian authorities, and kept sending requests for five months. (2) Revolut answered every one, as #FATF Recommendations and EU AML laws require. Refusal carries fines up to €5 million or 10% of turnover. Nothing in the rules obliges the bank to check whether the state behind the request is who it claims to be. Now scale this abuse a thousand times, in the hands of authoritarian states and their proxies, who do not seek attention like these hackers and quietly collect data on citizens and entities of the #EU and other Western countries. (3) The attackers claim to hold 147 GB from the #Italian side, including internal documents and officer chat logs, and say most of the Revolut data concerns customers in #Switzerland, #France and #Hungary, with other countries affected. Passports and #KYC selfies of named individuals are being published daily until Revolut pays. Every bank, exchange, payment provider and #CASP in every jurisdiction that follows FATF rules is exposed the same way, because the rules oblige them to answer state requests and nobody is required to check whether the state behind the request is legitimate. Self-hosted wallets close one door. The moment your data touches a regulated intermediary the same channel opens. Human rights groups, victims and experts, with support of Open Dialogue Foundation, described this risk to the European Parliament three years ago with support of @jack @npub1kp7j...487l and few other bitcoiners. We proposed specific remedies, supported by the majority of the European Parliament. The European Commission and the Council removed every safeguard the Parliament adopted from the AML Regulation. That decision is why this is happening now. Three institutions have since named this transnational financial repression: (1) European Parliament resolution of 18 June 2026, under MEP Hannah Neumann leadership; (2) Council of Europe Resolution 2669 of 25 June 2026, rapporteur MP Efstathiou, with MP Wiechel pushing for an investigation and remedies; (3) OSCE PA in The Hague, July 2026, led by MP Mauro Del Barbe, with the most detailed focus on exactly these attacks. We are collecting witness statements to push for implementation. If you are a legal or security expert and want to support our work, DM me. You want fewer surveillance channels open on you? The political fight decides which safeguards go back into the law. Support the MPs and MEPs who pushed for remedies. Demand accountability from Commission and Council for the ones they rejected. Before the next leak names someone who does not have the means to move house. image
This week #Revolut confirmed it handed over customers' passports, verification selfies, home addresses, IBANs and full transaction histories, including #Bitcoin, to a fake government request. The email came from a real government agency's domain, and Revolut complied because the rules told it to. #FATF rules, transposed into #US, #EU and #UK law, oblige every regulated institution to keep this data and hand it over promptly to any state request, with fines in the millions for delay and none for handing over too much. Nobody is required to check whether the state behind the request is legitimate. Any exchange, on-ramp or card issuer you use sits under the same rules. Authoritarian states and their proxies have used these requests for years against critics, donors and businesses. We call it transnational financial repression. This time it reached bitcoiners at scale. Since 2022 the Open Dialogue Foundation has campaigned before EU regulators for the privacy of payments and asked the Bitcoin industry to join. We were grateful for the support of @jack , @npub1kp7j...487l and a few other bitcoiners. Most others laughed, saying we are losing time or it was not their business. In 2023 we won a majority in the European Parliament for our safeguards. The closed-door trilogue then removed most of them from the AML Regulation. We did not have enough loud voices from the industry to defend payment privacy, and now not only activists, but also bitcoiners, business people, donors - we all face the hunting of our data at scale. There is still a chance. In July 2026 OSCE Parliamentary Assembly parliamentarians adopted remedies against the weaponisation of AML/CFT laws and recognised transnational financial repression as a threat to the security of the OSCE area, which covers the US, Canada, Europe and Central Asia. This would have been impossible without the support of Atlas Network, @npub1elww...ctu9 and the Reynolds Foundation (@npub1hkt8...ltpw ), who understood the problem at first sight. Will you keep observing and complaining, or join and make this space safe to use, invest and build in? There is nowhere else to run, if you understand how FATF rules work. If you don’t - happy to explain. Privacy has to be protected and normalised as a human right. Now, before it is too late.
Your Identity for Sale. Protect it NOW! For the last decade, governments across the world have followed Financial Action Task Force (FATF)'s mantra: we need full transparency and to identify everyone for security, for "better protection". This statement has not only proven to be a great failure, but it has now become the main weapon against western society and its governments themselves. On Aug. 31, Brian Krebs reported that a new service on the Russian cybercrime forum Exploit was offering access to digital scans of identity documents on more than 153 million people in North America. The FBI's New Orleans field office has launched an official investigation. How did more than 153 million identity documents from people in the United States and Canada end up in the hands of cybercriminals selling them on the dark web? Based on Krebs's interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by idscan.net, a widely-used identity verification company based in Louisiana that processes over 21 million verifications monthly at more than 20,000 locations, serving clients including Hertz, Target, FedEx, and Caesars Entertainment. The data had been continuously exfiltrated for over a year before it was discovered. For me this is also personal. As someone who has been subjected to the weaponisation of cybersecurity and financial laws by an authoritarian regime for my human rights work seeking to obtain my travel, financial, and communication data across the EU and the U.S., I know exactly what this kind of breach enables. Travel records, financial histories, and communication metadata are the most sought-after information for physical, economic, or digital attacks by authoritarian regimes and their proxies - we call it transnational financial repression. And I'm endlessly grateful for Mauro Del Barba, Markus Wiechel, Hannah Neumann for leading and pushing for clear remedies against these attacks at the level of the OSCE Parliamentary Assembly, Parliamentary Assembly of the Council of Europe, and European Parliament. This is real protection of our citizens and entities against cyberattack, not pushing for new aggregation of personal data! When 153 million identity documents sit in a single database for over a year, undetected, every person in that database becomes a potential target, not just for common fraud, but for transnational repression. Privacy has to be recognised as a fundamental human right, including in the digital space, where the same data that sits unprotected can be weaponised by bad actors and AI-powered tools alike. This is one more example of the message I'm not going to tire of repeating: the weaponisation of FATF's financial, national security and cybersecurity laws no longer serves as protection. Time to stop it and implement the most recent resolutions on transnational financial repression NOW. image