Revolut Leaked Customer Passports and Crypto Data via Spoofed Government Request
The fintech giant exposed sensitive PII after complying with a fraudulent data request sent via a spoofed official email.
Revolut has exposed the sensitive personally identifiable information (PII) of its customers after falling victim to a sophisticated phishing attack. The breach occurred when the company complied with a fraudulent government data request sent via a spoofed official email.
According to reports from ZeroHedge and The CyberSec Guru, the fintech firm failed to verify the authenticity of a request that appeared to come from government officials. This lapse led to the unauthorized disclosure of highly sensitive customer data, including passports, facial verification selfies, and Bitcoin transaction histories. The attackers successfully posed as government authorities to bypass security protocols and gain access to these records.
The Vulnerability of Digital Verification
Revolut currently serves over 80 million customers globally, positioning it as one of the largest fintech entities in the world. As the company moves toward a potential initial public offering (IPO), its internal security frameworks and the rigor of its compliance processes are under intense scrutiny. This incident reveals a gap in how the firm validates legal and governmental mandates, particularly those arriving through digital channels.
Implications for User Security
The exposure of identity documents and cryptocurrency activity creates a high-risk environment for the affected users. Passports and facial selfies are primary targets for identity theft and synthetic identity fraud, while the leak of Bitcoin transaction history compromises the financial privacy of users. For a financial institution, the failure to distinguish a spoofed email from a legitimate government directive suggests a critical vulnerability in its operational security.
Looking Ahead
Industry analysts are now watching to see if Revolut will overhaul its verification process for government requests to include multi-factor authentication or out-of-band verification. While the company has not yet detailed the exact number of affected accounts, the nature of the leaked data—specifically biometric and identity documents—means the security risk to these users is permanent. It remains to be seen if regulatory bodies will impose fines for the mishandling of sensitive PII.