Revolut, a UK-based fintech company, has admitted that it has accidentally passed on sensitive customer data to an unauthorized third party after receiving fraudulent requests, masquerading as a legitimate government agency.
The requests were sent from an email address of a legitimate government agency, and the firm was initially taken in by them, a Revolut spokesperson told Reuters. Once the fraud had been identified, Revolut blocked the address and reported it to the appropriate governmental agency, law enforcement and data-protection authorities and financial regulators.
Revolut stated that its own systems and customer funds weren’t affected. The company didn’t specify the number of customers involved.
The information exposed contained customers’ dates of birth, postal addresses, email addresses and phone numbers, TechCrunch reports, a fact cited by Reuters. Other information that was compromised included copies of identity documents such as driving licences and passports.

According to a customer notification that spread online, the information also could have contained know-your-customer verification materials and financial information, such as transaction history. The exact number of customers affected and which government agency is responsible have not been made public.
The challenge is that it was not easy to spot the faux official request, given that the attackers were able to send it using the real government email system and bypass normal email verification.
In fact, one of the largest fintech firms in Europe, Revolut has been intending a potential public listing and was looking for a valuation of up to $200 billion, according to Reuters.
Source: Reuters
