Revolut Exposed by Phishing Attack
Revolut, a British fintech company aiming for a $200 billion valuation and banking license, recently exposed sensitive customer data to an attacker through a convincing email. The phishing attack passed multiple security checks, including SPF, DKIM, and DMARC protocols, which are designed to verify the sender's identity.
The attack didn't require hacking any internal systems; it simply tricked Revolut's compliance team into handing over customer records. The exposed data included identity documents, verification selfies, financial records, and Bitcoin-related transaction activity.
This breach is unusual because it targeted Revolut's compliance workflow for responding to official government data requests rather than exploiting a technical vulnerability or compromised database.
The incident highlights the risks of social engineering attacks, which can be difficult to detect. In this case, no passwords were stolen, and customer funds remained intact, but personal and financial data walked out the door. Revolut has since blocked the unauthorized email address and notified law enforcement and regulatory agencies.