Phishing Attack on Revolut Exposes Customer Data and Bitcoin Histories
A phishing attack on Revolut's internal process for responding to government information requests has exposed sensitive customer data, including Bitcoin transaction histories.
The attacker created an email account within an official government authority's domain infrastructure that appeared legitimate and carried genuine domain authentication credentials. This allowed them to trick Revolut into providing customer information.
As a result, KYC data such as names, addresses, contact details, IDs, and verification selfies may have been exposed, along with IBANs, account statements, withdrawal records, and full transaction histories, including Bitcoin activity. This could potentially link real identities to crypto holdings and transactions.