Revolut Exposes Customers' Identity Documents in Fake Request Incident
A recent incident involving Revolut has exposed a targeted-fraud risk beyond account access.
The issue began when Revolut responded to a fake emergency government request, which was later determined to be fraudulent. In the process of verifying the request, sensitive information may have been released without an attacker first defeating a user's password or two-factor authentication.
The disclosed records included identity documents, account information, withdrawal records, and Bitcoin-related transaction history. However, it is crucial to note that private keys, seed phrases, or direct access to customer funds were not exposed.