**Revolut Exposes Sensitive Customer Data to Scammers, Reports Reveal**
In a troubling incident reported over the weekend, London-based fintech company Revolut has inadvertently disclosed sensitive customer information to scammers. This breach occurred after the company received fraudulent requests that were sent from an email domain resembling that of a legitimate government agency.
According to reports, including one from TechCrunch, the compromised data included critical personal information such as customers' birth dates, phone numbers, postal and email addresses, and copies of identification documents, including passports and driver’s licenses. Additionally, there are indications that verification selfies, account statements, and transaction histories may also have been exposed.
Revolut has acknowledged the breach, confirming to both TechCrunch and Reuters that a "limited" number of customers were affected. The company described the incident as a "sophisticated external impersonation scam," where an unauthorized third party successfully utilized a legitimate government agency's email domain to submit fraudulent requests for sensitive information.
Founded in 2015 by Russian-born entrepreneur Nik Storonsky, Revolut has positioned itself as a leading digital banking service, claiming to be the "world’s first truly global bank." The company currently serves over 80 million customers worldwide and has been actively expanding its operations internationally. Just over a month ago, Revolut received a banking license in France and has been enhancing its presence in various markets, including India, Mexico, and the UAE. Recently, the US Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a banking operation in the United States.
The timing of this data breach is concerning, particularly as police on the British island of Jersey had warned Revolut users of an increase in fraud cases. Reports indicated that victims had received phone calls from individuals impersonating Revolut's support or security teams, further highlighting the risks associated with the ongoing scams.
Revolut's practices have come under scrutiny in various countries in recent years. In April, Italian authorities imposed fines totaling €11.5 million (approximately $13.25 million) on the company for alleged unfair commercial practices. Additionally, the central bank of Lithuania fined Revolut €3.5 million last year, citing non-compliance with money laundering prevention regulations.
The recent data breach raises significant concerns about the security measures in place at Revolut and the potential implications for its customers. As the company continues to expand its services globally, it faces the challenge of maintaining robust security protocols to protect sensitive customer information from increasingly sophisticated cyber threats.
As investigations into the breach continue, affected customers have been notified by Revolut, and the company is likely to face scrutiny from regulatory bodies regarding its handling of sensitive data and the measures taken to prevent future incidents.