Revolut Falls Victim to Sophisticated Phishing Attack Exposing Customers' Sensitive Data
Revolut, a financial institution that offers banking services and cryptocurrency trading, has disclosed sensitive customer information to hackers. The company received a request from an unauthorized mailbox that mimicked a government agency's email address, complete with valid authentication credentials.
The request tricked Revolut into handing over customers' passports, verification selfies, Bitcoin transaction histories, and other personal data. The affected customers were informed that the disclosed information could include passport or driver's license copies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, and account statements.
Revolut has not identified the government agency involved in the request and has withheld the scope of the incident. However, on-chain investigator ZachXBT believes that the disclosure appeared to be limited in scale and may have targeted high-net-worth customers.
The immediate risk stems from the combination of identity documents, contact information, residential addresses, and financial histories now potentially available to the attacker.