Revolut Exposes Customers After Fake Government Email Request
Revolut has revealed that it released customer data after receiving a fake government email request. The incident did not involve a conventional intrusion into Revolut's networks.
The company says it handed over data because an unauthorized mailbox sitting inside an official public-authority domain sent a request with valid sender-authentication credentials.
According to the notice, the message was framed as a lawful agency request and passed common checks used to detect spoofed mail. Only later did Revolut learn that the mailbox was unauthorized after contacting the agency for confirmation.
The categories of information released included full names, dates of birth, occupations, home addresses, email addresses, phone numbers, copies of passports or driving licenses, verification selfies, IBANs, account statements, withdrawal logs, and complete transaction histories, including Bitcoin activity.