
British bank Revolut exposed sensitive customer information after falling for fraudulent requests sent from a legitimate government agency's email domain. In a statement shared with The Register, Revolut confirmed the attack, but did not specify how many customers were affected. The company also did not provide a list of affected data types. However, blockchain investigator ZachXBT, who shared Revolut's customer notifications on Friday, claimed the exposed information includes know-your-customer (KYC) data. Whichever identity document customers submitted as part of the account registration process - passport or driver's license - was compromised, as was the verification selfie submitted through the app, according to the shared emails. The notifications also list account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin transactions, among the exposed data. Other exposed details include full names, dates of birth, home and email addresses, phone numbers, and occupations. Sources close to the fintech say only a small proportion of its customers were impacted. They say ongoing investigations and confidentiality obligations prevent Revolut from providing further details. Revolut said it exposed the data to an unauthorized third party after they submitted requests from a genuine government agency's email domain. The company, which received approval to launch its UK bank in March, did not identify the government agency, but said it informed the relevant officials of the findings. "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson said. "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut systems and customer funds are unaffected. "We have contacted the limited number of impacted individuals directly to inform them and provide support." People claiming responsibility for the attack have posted in multiple Telegram groups. Posts seen by The Register include snippets of data that appear to belong to high-profile individuals, including CEOs, sports professionals, and performing artists. The posters are also threatening to release "more and more data every day until Revolut pays for leaking their customers," and are demanding 10,000 Bitcoin as a ransom, equivalent to more than $782 million. Revolut did not comment on the alleged ransom demands when asked. The company currently serves more than 80 million personal customers globally, as well as more than 800,000 businesses. Its co-founder and CEO, Nik Storonsky, has hinted at taking the fintech public, but not before 2028, with a target valuation of around $200 billion. (R)