In section Cryptocurrency

Revolut Leaks Customer Data After Sophisticated Email Spoofing Attack

A fraudulent request sent from a compromised government email domain has led Revolut to inadvertently disclose the personal and financial records of its customers. The banking firm, which boasts 80 million users, surrendered sensitive identity documents and Bitcoin transaction histories after the malicious email passed standard domain authentication security checks.

Revolut Leaks Customer Data After Sophisticated Email Spoofing Attack

The incident, first brought to light by on-chain investigator ZachXBT, involves an unauthorized party gaining access to an official government email account. Because the communication carried valid domain authentication credentials, Revolut staff processed the request under the assumption it was a legitimate regulatory inquiry. The company maintains that no internal systems were breached and no funds were withdrawn during the event.

The disclosed information represents a deep profile of affected users. Records provided to the unauthorized recipient included full names, dates of birth, home addresses, phone numbers, and copies of passports or driver’s licenses. Crucially, the breach extended to financial activity, including IBANs, account statements, and detailed Bitcoin transaction histories. While Revolut clarified that biometric facial telemetry and account passwords were not exposed, the combination of identity documents and transaction logs poses a significant risk for potential identity theft and targeted fraud.

Security and Regulatory Implications

ZachXBT suggested the breach appears limited in scope and may have specifically targeted high-net-worth individuals, though Revolut has not yet confirmed the total number of victims or the selection criteria used by the attacker. Under UK data protection standards, organizations are mandated to notify regulators of high-risk breaches within 72 hours. While the company has begun alerting affected customers via email, the timeline of the initial disclosure and the identity of the spoofed government agency remain undisclosed. The incident highlights a critical vulnerability in standard verification protocols where domain authentication is treated as a definitive proof of identity.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!