Revolut Exposes Sensitive Data After Failing to Verify Fake Government Request
A recent breach at Revolut, a financial institution, has exposed a subset of its customers' sensitive information. According to an alert shared by on-chain investigator ZachXBT, a fraudulent government request was made to Revolut, which the company failed to verify properly.
The affected users had their passports, verification selfies, full transaction histories, and home addresses exposed. This is not a routine phishing scam or leaked password list, but rather a targeted attack that could have serious consequences for those involved.
Financial institutions like Revolut receive legitimate government requests all the time, which they are required to comply with after proper verification. However, in this case, someone impersonated a government authority convincingly enough to get Revolut to hand over customer files without being detected.
The exposed data includes account statements, IBAN details, withdrawal records, and full transaction history, including Bitcoin activity. This is a complete picture of an individual's financial and identity information, which could be used for identity theft, spear-phishing, or extortion attempts.