FFC 6 September 728/250

Revolut Data Breach Exposes Information of Hundreds

Impersonation Scam Exposes Data of Revolut Customers

LONDON: (Business Desk) – British digital banking giant Revolut said Wednesday that an impersonation scam led to the disclosure of customer information to an unauthorised third party posing as a government agency.

A source familiar with the incident told AFP that around 680 Revolut customers across several European countries were affected by the breach.

Revolut said its banking systems and customer funds remained unaffected, adding that it had contacted the limited number of customers impacted by the incident and was providing them with support.

According to the company, the breach involved a sophisticated external impersonation scheme in which an unauthorised party used an email address linked to a legitimate government agency domain to submit fraudulent requests for customer information.

Revolut said it blocked the address as soon as the activity was detected and notified the relevant government agency, law-enforcement bodies, data protection authorities and financial regulators.

Britain’s Information Commissioner’s Office (ICO) confirmed to AFP that it had received a report concerning the incident and was assessing the information provided.

FFC 6 September 728/90

Italian media reported that the fraudulent emails may have originated from the prefecture of Reggio Calabria, although AFP said it had not independently verified the claim. Italy’s data protection authority has asked banks to review their data-access systems and report any security weaknesses, while police have opened an investigation.

An email sent to affected customers and reviewed by AFP said the compromised information included addresses, verification photographs, identity documents, banking activity details and information about bitcoin holdings.

Among those affected was French entrepreneur Mark Karpeles, who said he contacted police in Japan, where he lives, and moved with his family to a hotel as a precaution. Karpeles, the former head of Mt. Gox, said concerns over the targeting of cryptocurrency entrepreneurs had influenced his decision.

The Financial Times reported that individuals claiming responsibility for the incident had been in contact with Revolut for several months while allegedly using a false identity. The report said the attackers appeared to be targeting customers with significant cryptocurrency holdings, particularly in France and Switzerland.

The incident comes as Revolut continues its rapid international expansion. Founded in 2015, the fintech secured a long-awaited UK banking licence in March, allowing it to compete more directly with established retail banks. It also received conditional approval for a US banking licence this month and filed a banking licence application in Switzerland on Tuesday.

Revolut reached a valuation of $115 billion through a secondary share sale in July. The company, which initially focused on smartphone-based currency exchange and money transfers, now has more than 80 million customers worldwide and is targeting 100 million customers across 100 countries.

However, its rapid expansion has also attracted scrutiny over its compliance with financial regulations designed to prevent fraud and money laundering.

Comments are closed, but trackbacks and pingbacks are open.