Revolut, a prominent fintech company, recently experienced a data security incident where sensitive customer information was exposed. This occurred after the company responded to a fraudulent request that appeared to come from a legitimate government agency. The breach involved sensitive Know Your Customer (KYC) documentation and detailed financial records of a limited number of users. Exposed materials included passport and driver's license copies, identity-verification selfies, account statements, and complete transaction histories, including Bitcoin-related activities. According to Revolut, the incident did not result from a breach of its core systems or mobile application. Rather, it was due to a sophisticated impersonation attack using an unauthorized email account with a valid government agency domain. This led Revolut to mistakenly fulfill what it believed to be a legitimate request, providing extensive customer details such as full names, dates of birth, and contact information. The incident poses significant identity-theft and impersonation risks to affected individuals. The inclusion of cryptocurrency transaction records is particularly concerning, as it may allow criminals to profile victims for targeted scams. Revolut classified the event as a social-engineering attack rather than an internal systems breach. The company acted swiftly to block the unauthorized email, notify authorities, and inform affected customers, maintaining that customer funds were secure. This incident highlights the security challenges surrounding mandatory KYC data collection in financial and cryptocurrency sectors. It underscores the need for organizations to rigorously validate high-risk information requests, using independent channels rather than relying solely on domain authentication.
Revolut Incident Exposes Security Flaws in KYC Protocols
Revolut misdirected KYC request led to exposure of passport scans and full transaction histories for a subset of customers.
Executive Summary
PremiumActionable Insights
PremiumOriginal source
cybersecuritynews.com

