Brief news:
Someone (a scammer) used a real government agency email domain (not a forged fake domain). They opened an unauthorized account in it and sent Revolut a request for “official access to customer information.”
Because the email was sent from a genuine government domain and passed standard identity checks such as SPF, DKIM, and DMARC, Revolut believed it was a legitimate government requirement and handed over customers’ sensitive data.
Later, Revolut noticed something was wrong, realized it was a scam, immediately blocked that email address, informed affected customers, and reported the matter to relevant government agencies, the police, data protection authorities, and financial regulators.
This was not a hacking intrusion into Revolut’s systems. Instead, they themselves “believed a fake government email” and proactively provided the information.
The number of people affected was “a limited small portion.” The company did not disclose specific figures, though there are claims that it may have been skewed toward high-net-worth users.
What information was leaked?
The leaked items included: passport and driver’s license copies, identity verification selfie photos, name, date of birth, occupation, residential address, email, phone number, bank statements, IBAN account, wallet reference number, withdrawal records, and complete transaction history (including Bitcoin transactions), among other information.
#Revolut遭假政府邮件骗取用户数据
Note:
Revolut: A major British fintech company (similar to a digital bank), offering services such as multi-currency accounts, cross-border transfers, and cryptocurrency buying and selling. It has many users and no physical branches
Someone (a scammer) used a real government agency email domain (not a forged fake domain). They opened an unauthorized account in it and sent Revolut a request for “official access to customer information.”
Because the email was sent from a genuine government domain and passed standard identity checks such as SPF, DKIM, and DMARC, Revolut believed it was a legitimate government requirement and handed over customers’ sensitive data.
Later, Revolut noticed something was wrong, realized it was a scam, immediately blocked that email address, informed affected customers, and reported the matter to relevant government agencies, the police, data protection authorities, and financial regulators.
This was not a hacking intrusion into Revolut’s systems. Instead, they themselves “believed a fake government email” and proactively provided the information.
The number of people affected was “a limited small portion.” The company did not disclose specific figures, though there are claims that it may have been skewed toward high-net-worth users.
What information was leaked?
The leaked items included: passport and driver’s license copies, identity verification selfie photos, name, date of birth, occupation, residential address, email, phone number, bank statements, IBAN account, wallet reference number, withdrawal records, and complete transaction history (including Bitcoin transactions), among other information.
#Revolut遭假政府邮件骗取用户数据
Note:
Revolut: A major British fintech company (similar to a digital bank), offering services such as multi-currency accounts, cross-border transfers, and cryptocurrency buying and selling. It has many users and no physical branches
