Revolut Reveals Breach After Attacker Impersonates Government Agency

Fintech giant Revolut is disclosing a data breach after an attacker impersonating a government agency successfully requests sensitive customer information via email. The company says the request carries valid domain authentication credentials, leading staff to fulfill it under the reasonable belief that it is legitimate. Revolut, which serves more than 80 million customers across 160 countries, says the breach affects a limited number of customers but declines to share an exact figure.

The exposed data includes full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers. It also includes copies of identity documents such as passports and driver's licenses, facial verification selfies used for Know Your Client checks, IBAN numbers, account statements, withdrawal records, and full transaction histories, including Bitcoin transactions. Crypto fraud investigator ZachXBT says the attack appears to target high net worth users.

Revolut says it blocks the attacker's address upon detection and alerts the impersonated government agency, law enforcement, data protection authorities, and financial regulators. The company emphasizes that its systems and customer funds remain unaffected. This is not Revolut's first incident, as the company disclosed a 2022 breach that exposed the personal and financial information of more than 50,000 customers.

Read More at the original source →