Revolut Discloses Customer Data Following Fraudulent Government Request
Revolut has recently acknowledged that it fell victim to a sophisticated impersonation attack, leading to the unauthorized disclosure of customer data. Reports indicate that some customers were informed that their personal and financial information, including Bitcoin transaction histories, was shared in response to a fraudulent government request.
The request was sent from an email address that appeared to belong to a legitimate government agency and included valid domain authentication credentials. The exposed data comprised full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Additionally, sensitive identity verification documents such as passport copies and selfies were also disclosed.
According to ZachXBT, a blockchain investigator who highlighted the breach, the incident seems to have targeted high net worth individuals. Revolut has stated that it blocked the sender immediately upon realizing the fraud and has notified the relevant authorities, including the police and data protection regulators.
While Revolut assured that its systems and customer funds remain secure, the incident raises concerns about the implications of such data exposure, particularly given the sensitive nature of the information shared. The company has yet to disclose which government agency's domain was used in the fraudulent request, citing an ongoing police investigation.
FAQ
What happened with Revolut's customer data?
Revolut disclosed customer data following a sophisticated impersonation attack that led to unauthorized sharing of personal and financial information in response to a fraudulent government request.
What type of customer information was exposed?
The exposed information included full names, dates of birth, occupations, postal addresses, email addresses, telephone numbers, and sensitive identity verification documents such as passport copies and selfies.
How did the fraudulent request appear legitimate?
The fraudulent request was sent from an email address that looked like it belonged to a legitimate government agency and included valid domain authentication credentials.
What actions has Revolut taken in response to the incident?
Revolut blocked the sender of the fraudulent request immediately upon realizing the fraud and has notified the relevant authorities, including the police and data protection regulators.
Is Revolut's system and customer funds secure after the breach?
Yes, Revolut has assured that its systems and customer funds remain secure despite the data exposure incident.
Comments
Comments are moderated before publish.
No comments yet — be the first.