Revolut exposed customer data including passport copies, verification selfies and complete transaction histories to a fraudster using a legitimate government agency email domain. The fraudulent request bypassed Revolut’s authentication checks. The company blocked the address, alerted the relevant government agency and notified enforcement agencies and financial regulators. Customer funds remained unaffected and a limited number of impacted individuals were notified.
Source: Read the original article

