Revolut Exposed Customer Data to Fake Government Request
A sophisticated impersonation attack led Revolut to disclose customer information in response to a fraudulent government data request. The company says its systems, account credentials, and customer funds remained unaffected by the incident.
The reported scam surfaced after blockchain investigator ZachXBT shared customer notification texts. Those notices listed identity records, IBANs, statements, and Bitcoin transaction histories, but excluded biometric facial telemetry and passcodes.
Revolut says a limited number of customers received notices, while no funds left users' accounts. The company has not named the agency involved, citing a live police investigation.
ZachXBT described the incident as likely targeted at high-net-worth users, saying the group may have been selected for its wealth. Revolut says it blocked the sender after identifying the request as fraudulent and alerted the agency, police, financial regulators, and data protection authorities.