Bitcoin · United Kingdom · U.S. · The Block
Revolut confirms customer KYC, Bitcoin transaction data exposed after fake request from gov’t domain
Compiled by KHAO Editorial — aggregated from 3 sources. See llms.txt for citation guidance.
✓ KHAO Verified
Revolut disclosed sensitive customer information to an unauthorized third party that submitted fraudulent requests for records from a legitimate government agency email domain, the company told TechCrunch on Saturday.
Key facts
- The company also alerted the relevant government agency, law enforcement, data protection authorities and financial regulators, the spokesperson told The Block
- The incident comes as the British fintech firm seeks to expand its banking and crypto operations in the United States
- The Revolut incident is the latest in an ongoing string of customer-data security incidents involving crypto and related fintech firms
- Last month, crypto wallet provider SafePal said a flaw in an order-tracking system exposed names, contact information, shipping addresses and purchase details belonging to approximately 39,798
Summary
A Revolut spokesperson described the incident to The Block as a "sophisticated external impersonation scam" and said the company blocked the email address after identifying it. Revolut said a limited number of customers were affected and that it has contacted them directly, with some of the customers reporting receiving emails on Friday. The information disclosed may have included customers' names, dates of birth, postal and email addresses, telephone numbers and copies of identity documents including passports and driver's licenses, according to a notification sent to affected customers. A copy of Revolut's notice to customers shared publicly by former Mt.