Fintech company Revolut has disclosed a data breach after sharing information from an undisclosed number of customers with a threat actor impersonating a government agency.
The attacker requested personally identifiable information (PII) through an email sent from the agency’s official domain. Revolut said the message carried valid domain authentication credentials, so the request was fulfilled under the belief that it was genuine.
The exposed data may include customers’ full names, dates of birth, occupations, postal and email addresses, telephone numbers, passport or driver’s-license copies, and facial-verification images submitted for Know Your Client checks. It may also include account statements with IBAN numbers, withdrawal records, and complete transaction histories, including Bitcoin transactions.
Revolut said the breach affects a “very limited” number of customers but has not disclosed an exact figure. The company said its systems and customer funds were unaffected, and that it blocked the address and notified government, law-enforcement, data-protection, and financial-regulatory agencies.
Crypto fraud investigator ZachXBT said the incident likely involved a limited number of customers and appeared targeted at high-net-worth users. Revolut previously disclosed a breach involving 50,150 customers in September 2022. The company operates in over 160 countries and regions and serves more than 80 million customers, including 800,000 business customers.
Comments
0No comments yet. Be the first to comment.