In the United Kingdom, Revolut disclosed customer data through fake requests purportedly from a government agency — TechCrunch
British fintech company Revolut confirmed that it disclosed confidential customer data to an unauthorized third party after receiving fraudulent requests sent from an email address on the domain of a legitimate government agency. TechCrunch reports.
The company said the incident affected a “limited” number of customers, whom it contacted directly. Revolut did not specify the exact number of those affected. The company also did not clarify whether the case was limited to a particular market and did not disclose the name of the government agency whose domain was used to send the requests.
What data was disclosed
A notice to customers reviewed by TechCrunch said that the disclosed data included identification and contact information: dates of birth, postal and email addresses, phone numbers, as well as copies of documents, including passports and driver’s licenses.
More current news is available on the UA.News Telegram channel Telegram.
According to Revolut, the information may also have included verification selfies, account statements, and transaction histories. A company spokesperson described the scheme as sophisticated external impersonation fraud: an unauthorized party used an email address on the domain of a legitimate government body to submit false information requests.
Company response
After detecting the scheme, Revolut blocked the relevant email address and notified the government agency, law enforcement authorities, and relevant regulators. The company stressed that its systems and customers’ funds were not affected.
Cryptocurrency security researcher ZachXBT, who published information about Revolut’s letter to affected customers, suggested that the incident may have targeted users with significant wealth. According to information on Revolut’s website, the company has more than 80 million customers worldwide and operates as a bank in more than 30 countries.