Revolut Exposes Sensitive Customer Data After Fake Government Request
Revolut, a popular fintech company, has revealed that it inadvertently exposed sensitive customer information after receiving what appeared to be an authentic government request. According to on-chain investigator ZachXBT, Revolut disclosed highly sensitive personal and financial data belonging to certain customers.
The exposed records included passports, verification selfies, addresses, and complete Bitcoin transaction history. The company sent emails to the affected users, admitting that the exposed records were accessed under the belief that the request was legitimate.
Revolut explained that it received a request for information from an unauthorized email account using a government agency's actual email domain and carried valid domain authentication credentials. However, the company has not publicly named the government agency involved in the incident.
The incident appears to be an unauthorized disclosure rather than a direct compromise of Revolut's infrastructure. The company instructs government and law-enforcement bodies to submit official information requests through a dedicated channel.