Passports, selfies and financial transaction histories of some customers were revealed to a fraudster using a government agency domain.
Financial tech and banking company Revolut released sensitive customer data, including copies of passports, verification selfies and full transaction histories after receiving a fraudulent request that seemed to be from a government agency.
Requests for customer information sent from a legitimate government agency email domain passed Revolut’s authentication checks, according to International Cyber Digest posting on X. Revolut later concluded they were not authentic, and customers whose information was compromised were notified on Friday.
A company spokesperson told Cointelegraph on Saturday that “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
Read more





Be the first to comment