1 week ago
Genuine Government Email Reportedly Fooled Revolut in Data Breach
A hacker allegedly pretended to be a government official using a real government email address.
The hacker asked Revolut for private customer information.
Revolut reportedly believed the request and shared the information.
The data may have included passports, bank details, addresses, identity documents and photographs.
Records about Bitcoin activity were also reportedly included.
Revolut later discovered the request was a trick and blocked the email address.
The company contacted about 680 customers who may have been affected.
The hackers have reportedly threatened to release the information unless Revolut pays money.
The UK data watchdog is investigating what happened.
A hacker allegedly used a legitimate government email address to request Revolut customer information.
Revolut reportedly released sensitive data before discovering the request was fraudulent.
About 680 customers were reportedly contacted, with data including passport and bank details.
The Information Commissioner’s Office is investigating after Revolut reported the incident.
Revolut said customer funds and its systems were not affected, while hackers allegedly demanded a ransom.
- Who
- Revolut, an alleged hacker, about 680 potentially affected customers, and the UK’s Information Commissioner’s Office.
- What
- A fraudulent request sent from a genuine government email address allegedly led Revolut to disclose sensitive customer information.
- Where
- The incident involved Revolut and the UK’s data-protection regulator.
- When
- The timing of the incident is not specified; the ICO announced its investigation on Monday, and Mark Karpelès said he was warned on September 12.
- Why
- The alleged hacker used social engineering to make a fraudulent information request appear genuine.
Revolut’s Position
Customer and Oversight Concerns
Impact on Revolut systems and funds
Revolut’s Position
Revolut said its systems and customer funds were not affected, and that it blocked the address after detecting the deception.
Customer and Oversight Concerns
The incident nevertheless reportedly exposed highly sensitive personal and financial information belonging to hundreds of customers.
Verification of official requests
Revolut’s Position
The request reportedly appeared to come from a verified government email address, and Revolut said it notified regulators and affected customers after discovering the problem.
Customer and Oversight Concerns
Mark Karpelès questioned why further checks were not carried out before the information was released, even though the address appeared genuine.
Regulatory accountability
Revolut’s Position
Revolut reported the incident to the regulator and contacted customers who may have been affected.
Customer and Oversight Concerns
The Information Commissioner’s Office is investigating whether Revolut handled the request in accordance with its obligations to protect customer information.
Key facts
- Reportedly affected customers
- 680 customers were reportedly contacted by Revolut.
- Information involved
- Reportedly included passport details, bank account numbers, home addresses, identity documents, verification photographs and Bitcoin-related records.
- Attack method
- An alleged social-engineering attack using a legitimate government email address.
- Regulator
- The UK’s Information Commissioner’s Office is investigating.
- Company response
- Revolut said it blocked the address, notified regulators and customers, and reported the incident.
- Account impact
- Revolut said its systems and customer funds were not affected.
- Extortion threat
- The hackers allegedly threatened to publish the information unless Revolut paid a ransom.
Quotes
Revolut
The fintech company involved in the reported data breach
“immediately blocked the address”
easterneye.biz







