Blockchain investigator ZachXBT said Revolut may have disclosed personally identifiable information after failing to detect a forged government data request. According to his post, the request appeared to come from a real government body and was sent through that agency’s official email domain. Because the message also carried valid domain authentication, Revolut reportedly treated it as legitimate and responded.
The data that may have been exposed includes names, dates of birth, occupations, home addresses, email addresses, phone numbers, passport or driver’s license copies, identity verification selfies, account statements, IBAN details, withdrawal records, and full transaction histories, including Bitcoin transactions. In a notification sent to users, Revolut said no biometric facial telemetry data was leaked. ZachXBT added that the scope may be limited for now, but the affected group appears to be skewed toward high-net-worth users. Multiple Revolut users reportedly received security incident notices yesterday. Revolut had previously advised users to verify suspicious messages through in-app customer support and avoid sharing personal or financial information.
Blockchain investigator ZachXBT said on Sept. 12 that Revolut may have exposed some users’ personally identifiable information after allegedly failing to identify a forged request for customer data from a government agency.
A request that appeared to come from a real agency
According to ZachXBT, Revolut had earlier received a request for customer information that appeared to come from a legitimate government institution. The email was sent through that agency’s official domain. Because the message also carried valid domain authentication, Revolut reportedly concluded that the request was genuine and responded to it.
What data may have been affected
The data potentially involved includes user names, dates of birth, occupations, home addresses, email addresses and phone numbers, as well as passport or driver’s license copies, identity verification selfies, account statements, IBAN details, withdrawal records and complete transaction histories, including Bitcoin transaction records.
In a notice sent to users, Revolut said no biometric facial telemetry data had been exposed.
High-net-worth users may have been the main target
ZachXBT said the scale of the incident may be limited at this stage, but based on the available information, it appears to have mainly affected high-net-worth users. Multiple Revolut users reportedly received related security incident notices yesterday.
Revolut had also previously reminded users to verify suspicious communications through in-app customer support and not provide personal or financial information.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.