Revolut Falls Victim to Sophisticated External Impersonation Attack
Revolut, the popular fintech company, has confirmed that it fell victim to a sophisticated external impersonation attack. Fraudsters tricked Revolut into handing over sensitive customer data, including passports and Bitcoin transaction records, after sending a fake request from a real government agency email domain with valid credentials.
The attackers used a legitimate government agency domain email to submit fraudulent requests for information, which Revolut's systems initially believed was genuine. However, as soon as the issue was spotted, Revolut blocked the sender and took steps to mitigate the damage.
Revolut has assured its customers that their accounts remain secure, with no money moved or biometric data exposed. The company has also alerted the relevant authorities, including the police and financial regulators, and is working closely with them to investigate the incident.
The attack appears to have targeted a small group of wealthy users, with blockchain investigator ZachXBT highlighting that the leak was aimed at this specific demographic.