Revolut Hacked: Fake Government Request Exposes Sensitive Customer Data
A phishing attack on digital banking giant Revolut exposed sensitive customer data, including IDs, addresses, and Bitcoin [BTC] transaction histories.
The fake government request was sent to Revolut's security team, which treated it as genuine due to its legitimate email address and technical authentication credentials.
Revolut later discovered the request was fraudulent and blocked the attacker, notifying affected customers and regulators. The company revealed that the request originated from an unauthorized email account created within a government authority's domain infrastructure.
The exposed data may have included KYC information, IBANs, account statements, withdrawal records, and full transaction histories, including Bitcoin activity.