By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Revolut Customer Data Exposed Via Fake Government Email Impersonation

Fintech innovator Revolut announced on March 20, 2024, that a sophisticated fraudster successfully infiltrated its systems, gaining unauthorized access to a subset of customer data. The breach was orchestrated through a social engineering attack, where the perpetrator impersonated a legitimate government agency by utilizing a spoofed email address that mimicked an official government domain. This deceptive tactic led a Revolut employee to inadvertently disclose sensitive customer information. The compromised data is reported to include highly personal identification documents, such as scans of customer passports and selfies, alongside detailed records of their financial transaction histories. Crucially, Revolut has emphasized that the incident did not result in any compromise of customer funds, nor did it grant the fraudster direct access to customer accounts. Furthermore, sensitive financial credentials like card details and personal identification numbers (PINs) were not exposed during this breach.
Upon detecting the unauthorized access, Revolut immediately launched a comprehensive internal investigation to ascertain the full scope and impact of the incident. The company has proactively commenced the process of notifying all customers who may have been affected by the data exposure. These customers are being provided with guidance and support to help them safeguard against potential identity theft and future fraudulent activities. Revolut is also actively collaborating with relevant regulatory authorities and law enforcement agencies to thoroughly address the situation and prevent recurrence. While the precise number of individuals whose data was compromised has not been publicly disclosed, Revolut has indicated that the breach affected a limited cohort of its user base. Details regarding the specific government agency that was impersonated or the precise duration of the fraudulent access remain undisclosed at this time.
This incident underscores the persistent and evolving cybersecurity threats that financial institutions, including prominent fintech companies like Revolut, and their customers face. Social engineering tactics, such as phishing and domain spoofing, continue to be potent tools for malicious actors. Revolut, a significant player in the global digital banking and payments landscape, serves millions of customers worldwide, offering a wide array of services from international money transfers and currency exchange to cryptocurrency trading. Maintaining robust security protocols and customer trust is paramount for such organizations. In response to this breach, Revolut has stated it is implementing enhanced security measures and is undertaking a thorough review of its internal procedures and employee training programs to fortify its defenses against similar future attacks. The company continues to urge its customers to remain vigilant regarding their account activity and to report any suspicious communications or transactions promptly.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.