ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire

Personal, Financial Info Exposed in Revolut Data Breach

highData breachimportance 65
AI summary · glm-5.3

Revolut says a scammer using a legitimate government agency email domain obtained affected users' PII, ID copies, selfies and full financial records.

Revolut, a London-based neobank serving over 80 million users in 160 countries, notified affected users that personal and financial data was exposed to a third party posing as a government agency. Exposed data included names, addresses, dates of birth, driver's licenses, passports, verification selfies, IBANs, account statements, withdrawal records and full transaction history including Bitcoin. Revolut blocked the attacker's email and notified the relevant agency, regulators and law enforcement, but did not disclose how many individuals were impacted.

  • Attacker impersonated a government agency using valid domain email credentials
  • Exposed data includes ID copies, selfies, IBANs and full transaction history
  • Revolut serves 80+ million users across 160 countries
  • Affected user count undisclosed; systems and funds reportedly unaffected
Full article311 words · extracted from securityweek.com · click to collapse

British fintech giant Revolut is notifying a subset of users that their personal and financial information was compromised in a data breach.

Based in London, the neobank and financial technology company provides banking and investment services to over 80 million users in 160 countries and regions.

Late last week, the company informed a small number of users that their personally identifiable information (PII) was exposed to a third party posing as a government agency.

The exposed data, it said in emails to the affected users, included names, addresses, phone numbers, email addresses, dates of birth, occupation, copies of driver’s licenses and passports, and verification selfies.

Financial information, including IBANs, account statements, withdrawal records, and full transaction history, including Bitcoin, was also exposed.

The request carried valid technical domain credentials and was treated as an authentic agency inquiry. All financial institutions must comply with legal requests from law enforcement and government agencies.

Advertisement. Scroll to continue reading.

Responding to a SecurityWeek inquiry, a Revolut spokesperson confirmed the incident.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information.

After discovering the data breach, the company immediately blocked the attackers’ email address and notified the “relevant government agency as well as enforcement agencies, data protection, and financial regulators,” the spokesperson added.

According to Revolut, only a subset of its users was affected. However, the company did not say how many individuals were impacted.

“Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support,” Revolut’s representative said.

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: Telus Warns Customers of Account Breaches

Related: Phishing Research Challenges Conventional Security Awareness Testing

Related: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/personal-financial-info-exposed-in-revolut-data-breach/