Revolut disclosed a data breach after sending customer PII, financial records, and verification documents to an attacker who impersonated a government agency using a valid-looking email domain. The company said the incident affected a limited number of customers and that Revolut systems and customer funds were not impacted, while ZachXBT suggested high net worth users may have been targeted. #Revolut #ZachXBT
Keypoints
- Revolut shared customer data with a threat actor impersonating a government agency.
- The attacker used a government-like email domain with valid authentication credentials.
- Exposed data included names, contact details, ID documents, selfies, and transaction history.
- Revolut said the breach affected a limited number of customers and did not impact systems or funds.
- ZachXBT suggested the attack may have targeted high net worth Revolut users.