REVOLUT has confirmed a data security incident in which attackers impersonated a government body and used an email address from a genuine government domain to send fraudulent information requests. The company supplied sensitive customer data without verifying the requests, according to the report. Revolut said its systems and customer funds were not affected and that production systems were not directly breached through a network attack.
It described the number of affected customers as “limited”, although it has not published an exact figure, the affected countries, the impersonated body or how the attackers obtained authorisation for the email account.
Information disclosed to the fraudsters reportedly included names, dates of birth, addresses, email addresses, telephone numbers, passports, driving licences and other identity data. Some reports also alleged that identity-verification selfies, account statements, IBANs, withdrawal records and complete transaction histories were included.
The article says the data may enable targeted phishing, identity fraud and financial scams, while transaction details could reveal information about customers’ cryptocurrency activity.
The report claims the attackers specifically sought information about high-net-worth customers and warns that exposed financial and identity data could support physical “wrench attacks” — threats, kidnapping or violence intended to force someone to unlock a cryptocurrency wallet or transfer assets. However, it provides no evidence that such attacks have been attempted against Revolut customers. Revolut has not disclosed how long the fraudulent requests continued.