Revolut Leaks Customer Data to Unidentified Threat Actors
Revolut, a UK-based neobank, has inadvertently disclosed client information to unidentified threat actors. The institution shared personally identifiable information (PII) from an unknown number of users after receiving a request from an unauthorized government email account. Revolut delivered the data while complying with a request-for-information email that originated from an address hosted on a domain. The company stressed that the communication carried genuine domain authentication credentials, leading them to believe it was an authentic government agency request.
The shared information included key details such as names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Revolut also shared documents and verification data, including passport and driver’s licence images with facial verification pictures. This can expose customers to identity theft risks, particularly for high-net-worth individuals.
Marc Zeller, founder of the Aave Chan Initiative, was one of the customers affected by the leak. He posted on social media channels that 'woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way.'