Revolut disclosed sensitive personal and financial information belonging to certain customers after responding to a fraudulent request seemingly from a government agency. The compromised data included copies of passports, verification selfies, addresses, phone numbers, complete Bitcoin transaction histories, IBANs, and account-opening dates. The fake request originated from an unauthorized email account using a government agency’s actual domain with valid domain authentication credentials. On-chain investigator ZachXBT revealed the incident, describing it as likely limited in scope and targeting high-net-worth users. Revolut has not named the government agency involved or disclosed the number of affected customers, but stated that passwords, private keys, and funds were not accessed.
Source: Read the original article

