Revolut Exposes Sensitive Customer Data After Fake Government Request
Revolut has revealed that it inadvertently disclosed sensitive customer information after receiving what appeared to be an authentic government request. According to on-chain investigator ZachXBT, the company sent emails to affected users admitting that the exposed records included passports, verification selfies, addresses, and complete Bitcoin transaction history.
The incident occurred when Revolut received a request for information from an unauthorized email account using the actual domain of a legitimate government agency. The company fulfilled the request under the belief that it was legit, potentially disclosing customers' full names, dates of birth, occupations, home addresses, email addresses, and phone numbers.
However, Revolut emphasized that biometric facial telemetry itself was not compromised. The firm also revealed that it provided financial information, including account statements containing IBANs, account-opening dates, and wallet reference numbers, as well as withdrawal records and full transaction history, including BTC transactions.