Revolut discloses exposure of customer transaction data
Revolut confirmed on Saturday that an unauthorised third party obtained customer information through fraudulent requests sent from a legitimate government agency email domain. A spokesperson told The Block that the company blocked the address after identifying the impersonation.
The potentially exposed material included identity documents, account statements, IBANs and transaction histories, including Bitcoin transactions. Revolut said a limited number of customers were affected and had been contacted, but did not disclose the count or identify the agency.
The company said its systems and customer funds were unaffected. That leaves a separate privacy issue: records can link a person's identity and banking activity to transfers visible on a public blockchain.
The incident illustrates a weakness beyond custody technology. A convincing request through a trusted channel can expose sensitive financial information without an attacker taking control of a wallet.