Revolut over the weekend confirmed to multiple media outlets that it disclosed sensitive customer information to an unauthorized third party after that party submitted fraudulent requests for records using an email account on a legitimate government agency’s domain. A spokesperson reportedly described it as a sophisticated external impersonation scam and said Revolut blocked the address once it identified the fraud.
The purported notification sent to affected customers that has circulated online says exposed data includes listed names, dates of birth, postal and email addresses, telephone numbers and copies of identity documents including passports and driver’s licenses. Verification selfies, account statements and transaction histories, including Bitcoin. Mt. Gox CEO Mark Karpelès, who shared the notice, said he was affected.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
ZachXBT, who alerted followers on Saturday, said the incident appears to have been aimed at high-net-worth users. Revolut has not said how many users were affected and the government agency involved.
The attack adds to concerns around wrench attacks increasingly targeting crypto holders.
Hardware wallet maker Trezor disclosed a structurally similar problem last week, when a breach at its email provider let attackers send phishing from its own domain, days after saying a ShipMonk breach had exposed another 67,000 US customers.
Revolut, which says it has more than 80 million customers, won conditional approval from the U.S. Office of the Comptroller of the Currency this month to establish a national bank, began rolling out its EURR euro stablecoin in Denmark, Poland and Portugal in August, and is weighing a listing that could value it as high as $200 billion.
Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money
