Back Kucoin Revolut Confirms Limited Customer Data Breach via Impersonation Scam
ME News report, September 13 (UTC+8): Revolut disclosed that it inadvertently exposed sensitive customer information to an unauthorized third party, which submitted a fraudulent request for records using what appeared to be a legitimate government agency email domain. Revolut described the incident as a “carefully orchestrated external impersonation scam” and stated that it had blocked the email address upon identification. Revolut’s systems and customer funds were unaffected.
Revolut said the number of affected customers was limited and that it had contacted them directly. The leaked information may include customers’ names, dates of birth, mailing addresses, email addresses, phone numbers, and copies of identity documents such as passports and driver’s licenses. Additionally, self-portraits used for identity verification, account statements, and transaction records may also have been compromised.
Previously, ZachXBT monitored that Revolut allegedly leaked some users’ personal information due to failure to identify fraudulent requests. (Source: PANews)
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
