Revolut Exposed Sensitive Customer Records in Phishing Attack Demanding 10,000 BTC
Revolut, a popular fintech company, has disclosed sensitive customer records to an unauthorized party after receiving fraudulent data requests from an email address on a legitimate government domain. The incident occurred on September 12 and involved identity documents, verification selfies, account statements, and transaction histories containing Bitcoin activity.
The attackers used the guise of a government agency to trick Revolut's systems into handing over customer information. Revolut has confirmed that only a limited number of customers were affected and that its systems and customer funds remained unaffected.
The notification sent to affected customers listed birth dates, postal addresses, email addresses, phone numbers, and copies of identity documents such as passports and driving licenses. The company also disclosed that verification selfies, account statements, and transaction histories may have been exposed.
Revolut has taken steps to address the incident by blocking the sender's address, notifying regulators, and contacting affected customers directly.