Fintech company Revolut has disclosed a data breach after an attacker tricked the company into handing over sensitive customer information by impersonating a government agency.

The company said the attacker sent an email requesting customer information from an unauthorized account that appeared to use the official email domain of a legitimate government agency. Because the message passed valid domain authentication checks, Revolut believed the request was genuine and provided the requested data.

The breach affects a “very limited” number of customers, according to Revolut, although the company has not revealed exactly how many people were affected.

The information exposed includes customers’ full names, dates of birth, occupations, postal addresses, email addresses and phone numbers. In some cases, the data also included copies of identity documents such as passports and driving licenses, along with facial verification images used during the Know Your Customer process.

More sensitive financial information was also exposed. Revolut said the compromised data includes account statements containing IBANs, withdrawal records and complete transaction histories, including Bitcoin transactions.

Revolut operates across more than 160 countries and regions and provides banking, money management and investment services to more than 80 million customers worldwide, including around 800,000 business customers.

The company said its systems and customer funds were not affected by the incident. After discovering the breach, Revolut blocked the address involved and notified the relevant government agency, law enforcement authorities, data protection bodies and financial regulators.

READ
Telegram Desktop Flaw Could Hide JavaScript Inside Chat Exports

Crypto fraud investigator ZachXBT said the breach appears to have targeted a limited group of customers and may have focused on high-net-worth users.


Buy ExpressVPN with PayPal or Credit Card

This is not the first major data breach disclosed by Revolut. In 2022, the company reported another incident in which attackers stole personal, contact and financial information belonging to 50,150 customers.

Advertisement