1 week ago

Genuine Government Email Reportedly Fooled Revolut in Data Breach

Genuine Government Email Reportedly Fooled Revolut in Data Breach
How a genuine government email reportedly fooled Revolut · easterneye.biz

A hacker allegedly pretended to be a government official using a real government email address.

The hacker asked Revolut for private customer information.

Revolut reportedly believed the request and shared the information.

The data may have included passports, bank details, addresses, identity documents and photographs.

Records about Bitcoin activity were also reportedly included.

Revolut later discovered the request was a trick and blocked the email address.

The company contacted about 680 customers who may have been affected.

The hackers have reportedly threatened to release the information unless Revolut pays money.

The UK data watchdog is investigating what happened.

Key facts

Reportedly affected customers
680 customers were reportedly contacted by Revolut.
Information involved
Reportedly included passport details, bank account numbers, home addresses, identity documents, verification photographs and Bitcoin-related records.
Attack method
An alleged social-engineering attack using a legitimate government email address.
Regulator
The UK’s Information Commissioner’s Office is investigating.
Company response
Revolut said it blocked the address, notified regulators and customers, and reported the incident.
Account impact
Revolut said its systems and customer funds were not affected.
Extortion threat
The hackers allegedly threatened to publish the information unless Revolut paid a ransom.

Quotes

Revolut

The fintech company involved in the reported data breach

“immediately blocked the address”
easterneye.biz

Sources

Related news