Revolut Discloses Customer Data After Unauthorized Government Request
Revolut customers received an email informing them that their personal and financial data had been disclosed in response to a government request. The request, which was sent from an unauthorized email account using a government agency's official domain, contained valid authentication credentials.
The exposed data included full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Additionally, identity and verification information such as passport or driver's license copies and verification selfies were also shared.
Financial data disclosed included account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity. However, the email stated that biometric facial telemetry data was not shared.
Experts suggested that Revolut may have failed to recognize the request as fraudulent before sharing customer information.