Revolut Hit by Sophisticated Phishing Attack Exposing Customer Data
Revolut has confirmed that it was targeted by a sophisticated phishing attack, resulting in the unauthorized disclosure of sensitive customer information. The attack involved an email from a legitimate government agency's domain, which Revolut accepted as authentic and used to request access to customer files.
The company revealed that the attacker managed to obtain passports, driving licenses, home addresses, bank statements, and Bitcoin records belonging to a small group of users. However, Revolut emphasized that no money was moved, and passcodes, login details, and biometric data were not exposed.
Revolut has taken steps to contain the incident, including blocking the sender's email account and alerting relevant authorities, regulators, and affected customers. The company has also launched an internal investigation into the matter.