Revolut Falls Victim to Impersonator, Exposing Sensitive Customer Data
Revolut, a London-based digital bank with over 60 million customers worldwide, recently handed over customer files to an impersonator posing as a government agency. The incident highlights a vulnerability in authentication processes that allows attackers to obtain sensitive information without breaking into the system.
The attacker sent a request from an official-looking email domain, which Revolut's compliance team treated as genuine and released the records. However, the bank's system was not compromised, and no customer money was laundered.
The exposed set includes Bitcoin transaction histories alongside government ID and full account records, making it a treasure trove for phishers. The affected customers received security notices from Revolut, but the total number of affected accounts and the internal path the request took remain unclear.