Revolut Caught Out by Sophisticated Phishing Scam
Revolut has confirmed that it inadvertently disclosed customer data after fraudsters exploited a legitimate government email domain to submit fake requests for information.
The company said an unauthorised third party used a government agency's email domain to send fraudulent requests, exposing personal and financial details of a 'very limited' number of customers.
According to Revolut, the disclosed information may have included passports and driver's licenses, verification selfies, contact details, IBANs, account statements, and full transaction histories, including Bitcoin activity.