Revolut Mistakes Fraudulent Gov Request, Leaks Sensitive User Data
Revolut, a fintech giant serving over 80 million customers globally, has disclosed a data leak involving sensitive user information after it mistakenly treated a fraudulent government information request as legitimate.
The incident occurred when an unauthorized sender used an official government agency's actual email domain to send the request, which passed domain authentication checks. Revolut fulfilled the request under the reasonable belief that it was an authentic government agency request.
The leaked data includes full names, dates of birth, occupations, addresses, ID documents, verification selfies, IBANs, account-opening dates, Bitcoin wallet reference numbers, withdrawal records, and complete transaction histories. However, biometric facial telemetry data was not part of the disclosure.