Revolut falls for fake government requests, hands over customer data
Passports, selfies, transaction histories exposed as self-proclaimed culprits demand 10,000 Bitcoin
British fintech company Revolut experienced a data breach after responding to what appeared to be genuine government agency requests for sensitive customer information. In a statement to The Register, Revolut confirmed the incident but did not disclose the number of customers affected or the specific data compromised. Blockchain investigator ZachXBT, who shared Revolut's customer notifications, stated that the exposed data includes Know-Your-Customer (KYC) information, such as identity documents and verification selfies.
The notifications also revealed account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin transactions. Other details exposed were full names, dates of birth, home addresses, email addresses, phone numbers, and occupations. Sources close to the fintech firm suggest that only a small percentage of customers were impacted, but ongoing investigations and confidentiality obligations prevented Revolut from providing more information.
The company informed the relevant officials about the breach and took immediate action to block the unauthorized third party. Revolut's spokesperson assured that the company's systems and customer funds remained unaffected. High-profile individuals, including CEOs, sports professionals, and performing artists, have claimed responsibility for the attack and are demanding a ransom of 10,000 Bitcoin (approximately $782 million) in exchange for not releasing more data.
Revolut, which serves over 80 million personal customers and 800,000 businesses globally, currently has a target valuation of around $200 billion if it goes public, according to co-founder and CEO Nik Storonsky.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.