On September 12, Revolut revealed that it had exposed confidential client data due to unauthorized requests submitted from an email account resembling a legitimate government domain. These fraudulent requests successfully passed the company's verification checks before being identified as malicious.
The data leak is concerning, potentially involving sensitive personal information tied to Bitcoin transactions, including verification selfies, account statements, and transaction histories. In response to the breach, Revolut has taken immediate action by blocking the fraudulent email address and notifying the relevant government agency about the misuse of its domain. However, the company has not disclosed how many customers were affected by this incident.
Revolut has reached out to customers whose data may have been compromised and implemented measures to prevent future fraudulent communications. This incident underscores the significant risks posed by such deceptive requests, especially when they appear to originate from trustworthy government sources.
