HeadlinesBriefing favicon HeadlinesBriefing.com

Revolut Data Breach via Fake Government Requests

Hacker News •
×

British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers' identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver's licenses. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.

A Revolut spokesperson confirmed to Tech Crunch that a "limited" number of customers were impacted and said the company had contacted those customers directly. Revolut did not disclose the exact number of impacted individuals or whether the incident was limited to a specific market, declining to disclose the government agency involved.

"Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson said. The company blocked the email address after discovering the scam and alerted the relevant government agency, law enforcement, and regulators, adding that Revolut systems and customer funds are unaffected.

London-based Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries. Crypto security researcher Zach XBT noted the incident appeared targeted at high net worth users. The breach comes as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion.