Home · Technology · Sep 12 archive
Revolut Confirms Customer Data Breach via Fake Government Requests
Confirmed
In Short: Revolut has confirmed a data breach affecting a limited number of customers after a sophisticated scam involved impersonating a legitimate government agency.
Revolut detected a 'sophisticated external impersonation scam' where a fraudulent request was made using a legitimate government agency domain email. The company immediately blocked the address and alerted relevant authorities, including data protection and financial regulators.
A Revolut spokesman told BNO News that the incident involved the release of personal identification information (KYC data) such as full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers, as well as copies of ID documents and selfies. The company also disclosed that account statements, transaction histories, and withdrawal records, including Bitcoin transactions, were exposed.
Zeller, a Revolut customer, expressed frustration on X, formerly known as Twitter, stating, 'The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or 'we will close your account in 20 days.
Revolut emphasized that customer funds and systems were unaffected, and the company is reaching out to affected customers to provide additional support, though it did not specify the number of people impacted. The name of the government agency involved was not disclosed due to an ongoing police investigation.
What's confirmed
- Revolut detected a 'sophisticated external impersonation scam' where a fraudulent request was made using a legitimate government agency domain email. The company immediately blocked the address and alerted relevant authorities, including data protection and financial regulators.
- A Revolut spokesman told BNO News that the incident involved the release of personal identification information (KYC data) such as full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers, as well as copies of ID documents and selfies. The company also disclosed that account statements, transaction histories, and withdrawal records, including Bitcoin transactions, were exposed.
- Zeller, a Revolut customer, expressed frustration on X, formerly known as Twitter, stating, 'The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or 'we will close your account in 20 days.
- Revolut emphasized that customer funds and systems were unaffected, and the company is reaching out to affected customers to provide additional support, though it did not specify the number of people impacted. The name of the government agency involved was not disclosed due to an ongoing police investigation.
What's still developing
- Financial institutions are legally required to comply with official requests from law enforcement or government agencies, which are typically communicated through verified email addresses.
- Revolut has more than 70 million customers in over 40 countries and is valued at $75 billion, according to figures released in May.
- A Revolut spokesperson told BeInCrypto the bank blocked the sender as soon as it spotted the problem.
- Passcodes, login details, and biometric data were never exposed, the bank told BeInCrypto.
- Revolut believed it was genuine and released the data.
- The fraudulent communication originated from a genuine government agency email domain and successfully cleared standard domain verification protocols. ⚠️ ALERT: Revolut falls for a FAKE government request, exposing sensitive personal information of customers in a disturbing data breach.
- Revolut disclosed that it complied with a fraudulent government request using a spoofed official email and valid credentials, exposing PII… pic.twitter.com/3RPO6OYs1N According to Revolut, the organization processed the request based on its seemingly legitimate characteristics.
- Blockchain investigator ZachXBT published the customer notification via Telegram on September 11.
