Revolut Breach Exposes Millions of Customer Details via Fake Government Email
Revolut has confirmed that an unauthorized third party used a fake government email to request customer information, exposing sensitive data for millions of users.
The breach occurred when a legitimate government agency's email domain was used to submit fraudulent requests for customer info. This allowed the attacker to access personal details such as birth dates, postal and email addresses, phone numbers, identity documents, verification selfies, account statements, and transaction data.
Revolut says that only a 'limited' number of its over 80 million customers were affected by this sophisticated external impersonation scam. However, the company did not disclose the exact number of impacted individuals or which government agency was involved.
The incident highlights how social engineering can deanonymize Bitcoin holders at mainstream financial platforms like Revolut, which has expanded its crypto footprint across the EU and beyond.