Revolut Exposes Sensitive Data After Receiving Fake Government Request
Revolut has revealed that it exposed sensitive personal and financial information belonging to certain customers after receiving what appeared to be an authentic government request.
The company sent emails to the affected users, admitting that the disclosed records included passports, verification selfies, addresses, and complete Bitcoin transaction history. In total, the exposed data may have included full names, dates of birth, occupations, home addresses, email addresses, and phone numbers.
Revolut fulfilled the request under the belief it was legitimate after receiving a request from an unauthorized email account using the government agency's actual email domain and carrying valid domain authentication credentials. However, the firm has emphasized that biometric facial telemetry itself was not compromised.