Revolut Tricked into Disclosing Sensitive Customer Data
Revolut, a popular digital banking service, has revealed that it was tricked into handing over sensitive information about its wealthy customers to hackers. The incident occurred when Revolut treated a fraudulent government request as legitimate and disclosed customer data, including passports, verification selfies, and Bitcoin transaction histories.
The affected customers were informed on Friday that the disclosed information could include copies of their passport or driver's license, verification selfies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, and account statements. Additionally, withdrawal records and complete transaction histories, including Bitcoin activity, may have been released.
The request came from an unauthorized mailbox operating within the domain infrastructure of a genuine government agency and carried valid authentication credentials. Revolut subsequently contacted the agency, determined that the request was fraudulent, blocked the address, and began notifying customers and regulators.
Compliance demands are under scrutiny as a result of this incident, with some questioning how much information financial institutions collect from customers and the controls used when governments seek access to these records. Marc Zeller, founder of the Aave Chan Initiative, criticized Revolut for disclosing customer data, stating that it happened shortly after he received a notification to provide additional information or face account closure.