Revolut Fooled by Fake Government Request Exposes Customer Passports and Bitcoin Records
Revolut, a UK-based fintech company, has disclosed sensitive customer data after being deceived by fraudulent government requests. The attackers used an email account on a legitimate government agency domain to appear authentic and obtain the information.
The potentially exposed records included passports, verification selfies, addresses, IBANs, and complete transaction histories, including Bitcoin activity. Revolut stressed that passwords, passcodes, and customer funds were unaffected.
The incident highlights a security weakness for banks and crypto platforms: attackers may not need to defeat a company's technical defenses if they can successfully impersonate an organization that is legally entitled to request customer records.