Revolut discloses customer data after spoofed government email
Revolut disclosed customer data, including Bitcoin transaction records, after complying with a fraudulent request that appeared to come from a government agency, the digital banking platform confirmed. The incident, which the company described as a sophisticated external impersonation attack, involved an unauthorized sender using a legitimate government agency's email domain and passing standard authentication checks. The disclosed information included personal identifiers such as full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Identity documents, including passport copies and driving licenses, were also shared, along with verification selfies customers provided during account setup. Revolut stated that biometric facial telemetry data was not compromised. Financial records formed a significant portion of the exposed data. Account statements, International Bank Account Numbers (IBANs), account-opening dates, withdrawal records, and full transaction histories were provided to the unauthorized requester.