Revolut Discloses Data Breach After Impersonated Government Request
Fintech giant **Revolut** has revealed a data breach stemming from an incident where customer data was shared with a threat actor impersonating a government agency. While the company states a limited number of customers were affected, the compromised information is extensive and includes highly sensitive personal and financial details.
Digital banking and money management platform **Revolut**, serving over 80 million customers globally, recently disclosed a data breach. The incident involved the unauthorized sharing of customer data with a threat actor who successfully impersonated a government agency via email.
### Deceptive Request Led to Data Disclosure
The company confirmed that the attacker used a government agency's domain in their email request for personally identifiable information (PII). **Revolut** stated, "As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request."
### Extensive Data Compromised
The information exposed in this breach is comprehensive and highly sensitive. It includes:
* **Identity Details**: Full name, date of birth, occupation.
* **Contact Details**: Postal address, email address, telephone number.
* **Document and Verification Data**: Copies of identity documents (passport and/or driver's license), facial verification images (selfies for Know Your Client verification).
* **Financial Information**: Account statements (including **IBAN** numbers), withdrawal records, and full transaction history, notably including **Bitcoin** transactions.
### Targeted Attack on High-Net-Worth Users?
While **Revolut** has refrained from disclosing the exact number of affected customers, they confirmed it was a "limited number." Crypto fraud investigator **ZachXBT** suggested that the attack might have specifically targeted "high net worth users."
### Immediate Action and Regulatory Alerts
Upon detecting the breach, **Revolut** stated they immediately blocked the fraudulent address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators. The company emphasized that **Revolut** systems and customer funds remain unaffected.
### A Recurring Issue
This is not the first data breach for **Revolut**. Four years prior, in September 2022, the company disclosed another incident where attackers stole personal, contact, and financial information belonging to 50,150 customers.