Key Facts

Revolut confirmed to TechCrunch that an impersonator using an email address on a government agency domain obtained customer data. Help Net Security reports that Revolut described the affected population as limited.

Technical Details

According to the report, customer notifications listed contact and identity-document data; they said verification selfies, statements, and transaction histories may also have been disclosed. Revolut said its systems and customer funds were not affected.

Impact & Mitigation

Revolut says it blocked the sender and notified relevant authorities. Financial institutions should require verified, out-of-band validation of sensitive government or third-party data requests and notify affected customers promptly.

Sources

By Allan