Fintech giant Revolut, which offers banking, lending, investing, and crypto services to more than 80 million customers worldwide, has exposed sensitive customer data to an unauthorized third party, TechCrunch reported on Sep. 12.
Founded in 2015, the British fintech giant announced early this month that it has received conditional approval from the U.S. Office of the Comptroller of the Currency (OCC) for its U.S. national bank charter.
Related: 67,000 more Americans using Trezor exposed to data breach
Sensitive data of Revolut users leaked
TechCrunch said a Revolut spokesperson confirmed the data breach, calling it “a sophisticated external impersonation scam.”
The report cited on-chain analyst ZachXBT, who posted the email Revolut sent to affected customers late Friday.
According to ZachXBT, the exposed identity-related data includes the following.
The exposed financial data includes the following.
ZachXBT said the incident appeared to target high net worth users. Revolut said a limited number of customers were affected but did not disclose how many.
The Street Roundtable reached out to Revolut for more details on affected crypto users but had not received a comment by the time of publication. We will update this report when the company responds.
Trending on TheStreet Roundtable:
How Revolut fell prey to fake government request
Revolut said it received fraudulent information requests sent from a legitimate government agency email domain.
Though the email account itself was unauthorized, it used the government agency’s official domain. Revolut fulfilled the request, believing it to be genuine.
Once Revolut became aware of the data leak, it blocked the email address and alerted the affected users, the relevant government agency, law enforcement, and relevant regulators.
Revolut said its systems and customer funds were unaffected.
Leaked Bitcoin transactions can lead bad actors to doorsteps
The Revolut leak is particularly concerning for crypto users because the attacker now has both their Bitcoin transaction histories and their postal addresses. In the worst case, that combination can lead a bad actor to a victim’s doorstep.
