Revolut Falls for Sophisticated Scam Exposing Customer Data
Fintech giant Revolut has fallen victim to a sophisticated external impersonation scam, where it handed over sensitive customer data to a malicious actor. The breach affected a limited number of high-net-worth users, who had their passport copies and full Bitcoin transaction histories exposed.
The scammer used an unauthorized email account with a legitimate government agency's domain to request customer information. Revolut, believing the message was genuine due to its valid authentication credentials, fulfilled the request. The exposed data included identity details, contact information, document and verification data, and financial data including account statements and withdrawal records.
Revolut spokesperson described the breach as a 'sophisticated external impersonation scam' where an unauthorized third party used a legitimate government agency domain email to submit fraudulent requests for information. The company said it had blocked the email address, alerted the agency, law enforcement, and regulators, and that its systems and customer funds were unaffected.
The breach has raised concerns about the security of personal data in the fintech industry, particularly among crypto holders. ZachXBT, a crypto investigator, noted that the incident appeared to target high-net-worth users, which could be linked to an increase in 'wrench attacks' against known crypto holders.