Revolut falls for fake government requests, hands over customer data

← Back to the feed

Revolut falls for fake government requests, hands over customer data

The Register · 1 hour ago

Revolut, the British digital bank, exposed sensitive customer data after falling for a sophisticated impersonation scam in which fraudsters used a genuine government agency's email domain to submit bogus requests for information. The incident matters because it compromised highly sensitive identity and financial records, and those claiming responsibility are now threatening to leak further data unless Revolut pays a substantial ransom, raising the prospect of ongoing harm to affected customers.

Exposed data reportedly includes passports or driving licences, verification selfies, account statements, IBANs, withdrawal records and full transaction histories, alongside names, dates of birth, addresses, phone numbers and occupations. Revolut says only a small proportion of its more than 80 million customers were affected and that it has notified those individuals along with regulators and law enforcement, insisting systems and funds remain secure. Those claiming the attack have posted samples on Telegram, including data allegedly belonging to high-profile figures, and are demanding 10,000 Bitcoin, worth over $782 million, threatening further leaks until payment is made.

  • Revolut leaked customer KYC data via a fake government email scam.
  • Passports, selfies, transaction histories and personal details exposed.
  • Attackers demand 10,000 Bitcoin (~$782m), threaten further leaks.

Business Crypto Government Politics

Read the full article at the source →