Revolut's Compliance Team Duped by Spoofed Government Email Request
Revolut, a London-based digital bank with over 60 million customers worldwide, has inadvertently shared sensitive customer data after its compliance team fell victim to a spoofed government email request. The attackers successfully obtained passports and driver's licenses, Know Your Customer (KYC) selfies, account statements, International Bank Account Numbers (IBANs), withdrawal records, and Bitcoin transaction histories for high-net-worth customers.
No funds were stolen or systems breached during the incident, but the compromised data poses a significant risk of highly personalized phishing attacks. Revolut is notifying affected customers individually rather than issuing a broad disclosure.
The attackers deliberately targeted high-net-worth accounts, and it's unclear what criteria they used to select these customers. The limited scope of the breach suggests that the attackers may have been attempting to target specific individuals or groups.