Revolut Users Hit by Sophisticated Phishing Scam Targeting High-Net-Worth Individuals
A sophisticated phishing scam targeted Revolut users by impersonating a government agency email domain. The attacker successfully obtained sensitive customer data, including passport and driver's license copies, identity verification selfies, full names, dates of birth, occupations, postal addresses, email addresses, phone numbers, account statements, IBAN numbers, wallet reference numbers, withdrawal records, and complete transaction histories, including Bitcoin (BTC) transactions.
High-net-worth users appear to have been targeted in the breach. Revolut confirmed that its systems and customer funds were unaffected, but declined to disclose how many customers were hit or which government agency was impersonated.
The company's spokesperson described the incident as 'a sophisticated external impersonation scam.' Revolut contacted affected customers directly and alerted relevant authorities, law enforcement, data protection authorities, and financial regulators.