Revolut Sensitive Data Exposed via Fake Government Email Request
Financial services company Revolut has revealed that sensitive customer information was exposed after an unauthorized party used a fake government email address to request data. The incident occurred on September 13, and Revolut notified affected customers and regulators immediately.
The fraudulent request appeared authentic because it came from an email account within the domain infrastructure of an official government authority, which carried genuine authentication credentials. However, upon closer inspection, Revolut determined that the sender's requests were fake.
The exposed records included identity documents, verification selfies, addresses, IBANs, account statements, withdrawal records, and full transaction histories, including Bitcoin transactions. The company said its systems and customer funds remained unaffected by the incident.