Fintech giant Revolut has revealed a significant data breach where sensitive customer information, including passports and transaction histories, was compromised via a sophisticated impersonation attack.
- Attackers impersonated a government agency using valid domain credentials.
- Exposed data includes passports, driver's licenses, and facial verification selfies.
- Financial records, including Bitcoin transaction histories, were leaked.
- Revolut claims customer funds remain unaffected.
Global fintech powerhouse Revolut, which serves over 80 million customers across 160 countries, has disclosed a major data breach. The incident occurred after the company inadvertently shared sensitive customer data with a threat actor who successfully impersonated a legitimate government agency.
The Mechanics of the Deception
According to communications sent to affected users, the attacker requested personally identifiable information (PII) via email. Crucially, the request originated from an unauthorized account that utilized an official government agency's email domain. Because the communication carried valid domain authentication credentials, Revolut acted under the reasonable belief that the request was an authentic government mandate.
Scope of the Compromised Data
The breach is not limited to simple contact details; it involves highly sensitive identity and financial markers. The leaked information includes:
- Identity Details: Full names, dates of birth, and occupations.
- Contact Information: Postal addresses, email addresses, and telephone numbers.
- Verification Documents: Copies of passports, driver's licenses, and KYC facial verification images (selfies).
- Financial History: Account statements, IBAN numbers, withdrawal records, and full transaction histories, including Bitcoin transactions.
Why This Matters
BozokMedia analysis shows that the combination of biometric data (selfies) and official identity documents (passports) creates a massive security risk for identity theft. Unlike a stolen password, a compromised passport or facial scan cannot be easily reset, leaving victims vulnerable to long-term synthetic identity fraud.
The ability of attackers to bypass domain authentication protocols highlights a critical evolution in sophisticated social engineering tactics.
While Revolut stated that the breach affects a "very limited" number of customers, they have declined to provide specific figures. However, crypto fraud investigator ZachXBT noted that the breach appeared to be highly targeted toward high-net-worth individuals, suggesting a calculated move by professional cybercriminals.
Historical Context
This is not an isolated incident for the fintech firm. In September 2022, Revolut disclosed another significant breach where the personal and financial information of over 50,000 customers was stolen by attackers.
Frequently Asked Questions
Q1: Is my money safe in my Revolut account?
A1: Yes, Revolut has officially stated that their core systems and customer funds are unaffected by this breach.
Q2: What should I do if my data was leaked?
A2: Monitor your financial statements closely, update your security credentials, and be extremely wary of any unsolicited communications requesting further info.