Revolut Falls Prey to Spoofed Government Email, Customer Data Exposed
Revolut, a digital banking platform, has fallen victim to a spoofed government email that compromised sensitive customer information. The incident occurred when Revolut mistakenly released customer data in response to a fraudulent request that appeared to be an official government correspondence.
The fake email originated from a legitimate government agency domain and successfully cleared authentication protocols, allowing the unauthorized recipient to obtain personal identifiers, passport documentation, verification photographs, and financial statements.
Bitcoin wallet identifiers and complete cryptocurrency transaction records were also leaked in the breach. Blockchain investigator ZachXBT suggested that the scope of the compromise appears contained and may have targeted affluent account holders.
Revolut has declined to specify which government agency's domain was exploited or provide details on how unauthorized individuals obtained access to official channels. The company emphasized that biometric facial recognition data remained secure, but banking records and cryptocurrency-related information were compromised.
The incident highlights the importance of robust security measures in preventing such breaches. Regulatory frameworks mandate that organizations report qualifying breaches within 72 hours and inform affected individuals without unreasonable delay.