Revolut Data Breach Exposes Hundreds of Customers
A recent data breach at Revolut has affected around 680 customers. The incident occurred when an extortion group sent fraudulent requests to Revolut, masquerading as a government body. These requests were deemed authentic by Revolut's compliance team, but the company later discovered the impersonation.
The requests contained sensitive customer information, including names, dates of birth, occupations, addresses, email addresses, and phone numbers. Some customers may have had their passports or driver's licenses exposed, along with selfies taken to verify identity. Financial data, such as IBANs, account openings, withdrawal information, and complete transaction history, were also potentially compromised.
The extortion group, known as Revolut Smilik, demanded 10,000 Bitcoins in exchange for not leaking the stolen files. Revolut refused to comment on whether they received or responded to this demand. The UK regulators are reviewing the incident, and an investigation is ongoing to determine how the attack was carried out.