Fintech firm Revolut reportedly disclosed personal and financial customer data, including Bitcoin transaction histories, after receiving a request that appeared to come from a legitimate government agency but was sent from an unauthorized email account. The fraudulent request used an official government agency domain with valid domain authentication credentials. Exposed data included full names, dates of birth, postal addresses, passport or driver’s license copies, verification selfies, account statements, IBANs, and complete transaction histories including Bitcoin activity. Experts suggested that Revolut may have failed to recognize the request was fraudulent before sharing customer information, with onchain sleuth ZachXBT noting the incident appeared to target high net worth users.
Source: Read the original article

