The Revolut exposed personal and financial information of some of its customers after fulfilling a fraudulent data request that appeared to have been sent by a legitimate government agency. The fintech notified affected users on Friday, the 11th, and the case was reported this Saturday, the 12th, by blockchain investigator ZachXBT.

According to the notification sent by the company, the request arrived through an unauthorized email account that appeared to belong to a public agency. After providing the information, Revolut contacted the agency involved directly to validate the request and found that it was not legitimate.

The incident constitutes an exposure caused by social engineering, and not by a technical intrusion into the fintech's infrastructure. The initial report states that there was no loss of customer funds.

Documents, IBANs, and transaction history were exposed

Among the affected information are copies of passports or driver's licenses, selfies used for identity verification, full names, dates of birth, occupations, home addresses, emails, and phone numbers.

The exposure also extended to financial data, including IBANs, bank statements, withdrawal records, and complete transaction histories, including transactions involving Bitcoin. Revolut informed customers that facial biometric telemetry data was not compromised.

The number of affected customers was not disclosed. ZachXBT stated that the incident appears to have limited scope but may have been aimed primarily at high-net-worth customers. The assessment was not publicly confirmed by Revolut.

The fintech's policy provides for sharing information with authorities when required by law. Revolut itself maintains a dedicated channel for official requests and court orders, which makes validating the origin of these requests a central step in the process.

More from Radar