Revolut Customers Hit by Fake Government Request Exposing Sensitive Data
Revolut revealed on September 13 that sensitive information belonging to a limited number of customers was exposed after an unauthorized party used an email account from a legitimate government-agency domain to send fraudulent data requests.
The company stated that the request appeared authentic due to its genuine domain-authentication credentials, but it later determined the sender's requests were fake. Revolut blocked the address and notified affected parties.
The exposed records included identity documents, verification selfies, addresses, IBANs, account statements, withdrawal records, and full transaction histories, including Bitcoin transactions.
Revolut emphasized that its systems and customer funds remained unaffected by the incident, characterizing it as a fraudulent disclosure request rather than an intrusion into its systems.