Revolut handed customer data to fraudsters using government email account
Revolut, a British fintech company with over 80 million customers, disclosed that it handed customer data to fraudsters who used a legitimate government email account to submit fake data requests. The attackers targeted high-net-worth individuals involved in crypto, and the breach followed a notification to users requesting extensive data submission. The incident highlights a growing trend of sophisticated phishing attacks leveraging compromised government accounts.
Revolut, a global fintech firm with over 80 million customers, has revealed that it inadvertently shared sensitive customer data with fraudsters. The company stated it recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information. The attackers specifically targeted high-net-worth individuals, many of whom are involved in cryptocurrency businesses.
Revolut indicated that the breach occurred after it sent out notifications to users requesting a significant amount of data, threatening account closure if compliance wasn’t met. Alleged extortion images circulated on Telegram by an account claiming to have perpetrated the attack suggested the email originated from an Italian domain.
One of Revolut’s customers, whose data was shared as proof of the breach, confirmed the information’s authenticity on social media. The exposed data included birth dates, postal and email addresses, phone numbers, passport and driver’s license copies, verification selfies, bank statements, international bank account numbers (IBAN), withdrawal records and transaction histories, including Bitcoin activity.
Marc Zeller, a cryptocurrency entrepreneur, reported that he awoke to find his data leaked by Revolut, following a notification requesting extensive data submission. Similar breaches have occurred in the past, with hackers linked to the Lapsus$ group using compromised law enforcement accounts and forged emergency data requests to obtain user information from companies like Apple, Meta, and Discord. The FBI has previously issued an alert about these fraudulent requests, noting an increase in postings on criminal forums offering access to compromised email accounts.
Revolut says it has notified the affected customers directly and has blocked the compromised domain. The company is considering a public listing that could value it at up to $200 billion.
