- Sources: TechCrunch, HN discussion
- Summary: An unauthorized third party submitted information requests from a legitimate government agency email domain and Revolut answered them. Revolut's statement describes the event as a sophisticated external impersonation scam and names no software vulnerability. Disclosed data includes dates of birth, postal and email addresses, phone numbers, and copies of passports and driver's licenses, and Revolut's customer notification states it may also have included verification selfies, account statements and transaction histories. Revolut says a limited number of customers were affected without publishing a count, has not named the agency or the markets involved, and states that it blocked the address, notified the agency, law enforcement and regulators, and that systems and customer funds are unaffected.
- Why it matters: The control that failed is identity verification of the requester on the emergency-disclosure path most large platforms operate, rather than anything in the product.
- Follow-up: Whether Revolut publishes an affected-customer count or names the agency involved.
send feedback on this story