Revolut shared sensitive customer data after fake government request

0
Clear media

British finance app Revolut shared sensitive information from a number of its customers, including KYC documents and full transaction histories, after complying with a request from someone who impersonated a government agency, the company confirmed on Saturday.

Revolut confirmed that a “limited number” of its customers were affected by a “sophisticated external impersonation scam” in which someone utilized a legitimate government agency domain email to submit fraudulent requests for information, which the company complied with, believing they were real.

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” a Revolut spokesman told BNO News. “Revolut systems and customer funds are unaffected.”

The information shared with the malicious actor included KYC information such as a customer’s full name, date of birth, occupation, postal address, email address, and phone number. It also included copies of ID documents such as passports or driver’s licenses and selfies taken by customers to confirm their identity.

The data also included account statements with IBAN numbers, account statuses, opening dates, and wallet reference numbers, as well as withdrawal records and a full transaction history, including Bitcoin.

Revolut said it was reaching out to affected customers to inform them of the incident and to provide additional support, though it declined to say how many people were affected. A person familiar with the matter described it as a “very limited group” of customers. The name of the government agency involved was not released.

One affected user, Marc Zeller, expressed his frustration on social media.

“The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or ‘we will close your account in 20 days’,” Zeller wrote on X, formerly known as Twitter.

Financial institutions are legally required to comply with official requests from law enforcement or government agencies, which are typically communicated through verified email addresses. It’s unclear how the malicious actor was able to use the government agency’s email domain.

Revolut has more than 70 million customers in over 40 countries and is valued at $75 billion, according to figures released in May. Earlier this month, Revolut received conditional approval for a national bank charter in the U.S., a major step in its push to launch an American bank by 2027.

The post Revolut shared sensitive customer data after fake government request appeared first on BNO News.

Ella Rae Greene, Editor In Chief

Leave a Reply

Your email address will not be published. Required fields are marked *