On September 12, Revolut revealed that it inadvertently disclosed confidential client data following unauthorized requests sent from an email account impersonating a legitimate government domain. These fraudulent requests successfully bypassed Revolut's verification checks until the company identified the breach.
The leaked information is particularly sensitive, potentially including personal details of customers associated with Bitcoin transactions. Data such as verification selfies, account statements, and transaction histories might have been compromised.
In response to the incident, Revolut has blocked the fraudulent email address and reported the misuse to the respective government agency whose domain was exploited. The company has not revealed how many customers were affected by this data breach.
Affected customers have been contacted, and measures have been taken to prevent any further communication from the fraudulent sender. This incident highlights the risks associated with fraudulent requests, especially when they originate from what appears to be a trusted government domain.
