United Kingdom
Revolut
British fintech Revolut confirmed it mistakenly handed over sensitive data belonging to nearly 700 customers to scammers posing as government officials.
Revolut disclosed that a fraudster used a real email account on a genuine government agency's domain to send fraudulent data requests. The messages passed the bank's technical authentication checks and were processed as standard legal compliance requests, as Revolut's systems had no way of distinguishing them from legitimate ones. The accidentally disclosed information includes customer addresses, verification pictures, identity cards and bitcoin activity belonging to around 680 customers.
Hackers purporting to be behind the incident are now threatening to release the stolen information publicly unless Revolut pays a ransom.
How it could affect your business
No servers were breached and no malware was deployed in this attack. Someone simply asked for customer data from what appeared to be a genuine government email address and the fintech handed it over. It is a stark reminder of how effective social engineering can be and how even technically robust systems can be bypassed when human judgment is the last line of defense. Businesses need to ensure that employees handling sensitive data requests are trained to spot manipulation attempts, verify requests through secondary channels and treat any unsolicited data request, however legitimate it appears, with a healthy level of scrutiny.
