2 Remove Virus

Revolut customer data exposed after scammers used government email domain

Revolut has confirmed that sensitive customer information was handed to unauthorized parties after scammers submitted fraudulent requests using an email account hosted on a legitimate government agency domain.

 

 

The financial technology company described the incident as a “sophisticated external impersonation scam.” The attackers did not need to break into Revolut’s systems. Instead, they sent requests for customer information that appeared to come from a government authority.

Because the requests originated from an email account within the agency’s legitimate domain, Revolut initially treated them as authentic and disclosed information associated with a limited number of customers.

The exposed information included names, dates of birth, occupations, postal and email addresses, telephone numbers and copies of identity documents such as passports and driver’s licenses.

Additional information may also have been disclosed. Notifications sent to affected customers indicate that verification selfies, account statements, IBANs, withdrawal records and complete transaction histories could have been included. For some customers, those histories also contained Bitcoin transactions.

Revolut has not disclosed exactly how many customers were affected. The company has described the number as limited and said those individuals were contacted directly.

The identity of the government agency whose email domain was used has also not been publicly revealed. It remains unclear how the unauthorized party obtained an email account within the agency’s domain.

After discovering the problem, Revolut said it blocked the email address involved and alerted the relevant government agency. Law enforcement agencies, data protection authorities and financial regulators were also notified.

The company said its own systems were not compromised in the incident and customer funds were unaffected. The available information therefore points to unauthorized disclosure through fraudulent information requests rather than attackers gaining direct access to Revolut’s banking infrastructure.

The incident is separate from a July claim in which someone offered what they described as 75 million Revolut customer records for sale. Revolut said at the time that it had found no evidence its systems had been breached in connection with that dataset.

In the latest case, however, Revolut has confirmed that customer information was disclosed to an unauthorized third party. The company has not publicly identified the government agency involved or provided an exact figure for the number of customers whose information was released.