Revolut Fooled by Fake Government Request Exposes Customer Data
Revolut revealed on Friday that hackers had tricked them into handing over sensitive customer information after treating a fraudulent government request as legitimate. The attackers gained access to passports, verification selfies, and Bitcoin transaction histories of wealthy customers.
The affected customers were told by Revolut that the disclosed information could include passport or driver's license copies, verification selfies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, and account statements. Withdrawal records and complete transaction histories, including Bitcoin activity, may also have been released.
The request came from an unauthorized mailbox operating within the domain infrastructure of a genuine government agency and carried valid authentication credentials. Revolut contacted the agency separately, concluded the request was fraudulent, blocked the address, and began notifying customers and regulators.