Revolut shared customer data with malicious actor via government domain
Revolut has handed over customer data to a malicious actor who posed as a government body. The attacker used an email address on a genuine government domain, which passed all standard authentication checks. Affected customers were informed last Friday. The leaked information includes passport copies, verification selfies and the full Bitcoin transaction history of the users involved.
In brief:
- Revolut handed customer data to a malicious actor who sent emails from a legitimate government domain.
- The leaked data includes identity documents, contact details, bank statements and transaction histories including Bitcoin.
- Revolut has blocked the email address involved and notified regulators.
Attacker used genuine government domain
The attacker sent an official-looking request for information from an email address that had actually been created on a government body’s domain. Because the email passed all domain authentication checks, Revolut treated the request as legitimate and provided the requested data.
Only later did the company conclude that the request was not authentic. Revolut has warned the body concerned about the unauthorised email address on its domain and subsequently blocked the address. Regulators have now also been informed. Revolut has not explained how the attacker gained access to a mailbox on the government domain.
What exactly was released
According to the notification received by affected customers, the following data may have been released: full name, date of birth and occupation, as well as home address, email address and telephone number. It also concerns copies of identity documents such as a passport or driving licence and the selfie customers submitted during verification. According to Revolut, biometric facial data was not involved in the incident.
Financial information was also shared, including bank statements with IBAN and account opening details, withdrawal attempts and the full transaction history, including Bitcoin transactions. Revolut has not disclosed how many customers were affected. Nor does the company name the government body involved.
Incident appears to target wealthy users
Researcher ZachXBT, who shared the customer notifications, believes the incident was limited in scope and targeted at wealthy users. It is therefore presumably a targeted attack rather than a broad data breach in which large numbers of customers were hit at random.
For customers who also hold Bitcoin via Revolut, the situation is particularly sensitive. A full transaction history gives an attacker detailed insight into spending patterns and a user’s possible wealth. At a time when Bitcoin is trading around $77.000, that information can be especially valuable to malicious actors.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.