Revolut Bitcoin Clients Exposed in Government Agency Email Scam
A recent data leak at Revolut exposed sensitive information of its clients to scammers. The incident occurred when a fake emergency request was sent from the real domain of an unnamed government agency, tricking Revolut employees into believing it was genuine.
The attackers gained access to the official email of the government agency and used it to contact Revolut. The key factor in this breach was that the email came from a real government domain, which passed internal checks without raising suspicion at the initial stage.
The scammers obtained sensitive information about major holders of Bitcoin, including passport scans, selfies for verification, home addresses, phone numbers, email addresses, bank details, and account statements. The leak also included bitcoin transaction history, which can be used to assess financial activity and link bank transactions to the movement of digital assets.
Revolut representatives confirmed the incident and emphasized that client funds were not affected. The company blocked the source of the fake request and passed information about the attack to law enforcement agencies.