Revolut recently fell prey to a sophisticated impersonation attack where hackers masquerading as government agency officials tricked the company into handing over sensitive customer information. The breach has resulted in the exposure of birth dates, contact details, identity documents, and transaction records, prompting fears of widespread identity theft.
- Hackers spoofed legitimate government email to request data
- Sensitive customer data including ID docs and crypto transactions accessed
- Ransom demand reaches $780 million with data leaks underway
What happened
Revolut was targeted by a highly sophisticated scam involving hackers impersonating official government agencies. These attackers either gained access to or forged legitimate government email addresses, enabling them to submit fraudulent information requests to Revolut. Believing these requests to be lawful, Revolut inadvertently shared a wide range of sensitive customer data.
The compromised data reportedly includes personal identifiers such as birth dates, postal and email addresses, phone numbers, and occupation details. More sensitive records were also exposed, including identity verification selfies, account statements, transaction histories, IBANs, withdrawal information, and even Bitcoin transaction records. The exact number of affected customers has not been disclosed, but Revolut has described the breach as limited and claims affected users have been notified.
Why it matters
This breach represents a major security failure for Revolut, a fintech renowned for its digital identity verification methods. By handing over such comprehensive information, the hackers obtained a complete identity theft toolkit capable of enabling fraudulent activities, such as opening accounts or bypassing security checks at other institutions.
The incident serves as a cautionary tale about the importance of stringent verification protocols when responding to data requests, especially for regulated financial entities managing highly sensitive personal information. The ramifications extend beyond a standard data breach, with the stolen data being sold as ready-made fraud packages of significant value on dark web markets.
What to watch next
Revolut has responded by blocking the compromised domain, alerting government and enforcement agencies, and notifying relevant data protection and financial regulators. The company’s ongoing response and any legal or regulatory actions ensuing from this incident will be closely observed by the cybersecurity and fintech communities.
Meanwhile, attackers have begun leaking fragments of stolen data on Telegram to pressure Revolut into paying an unprecedented ransom demand estimated at 10,000 bitcoins, roughly $780 million. Monitoring how Revolut and authorities handle this extortion threat will provide critical insights into crisis management and ransom negotiation strategies in future digital banking security breaches.