British fintech company Revolut confirmed that it disclosed sensitive information belonging to some customers to an unauthorized third party after receiving fraudulent requests sent from a legitimate email domain belonging to a government institution. The incident was disclosed in an email notification sent to affected customers, according to TechCrunch.
The exposed data included identification and contact information, such as dates of birth, postal and email addresses, and phone numbers. Copies of identity documents, including passports and driving licenses, were also disclosed.
Revolut stated that the information accessed may also have included selfie photographs used for identity verification, bank statements, and transaction history. In the information cited, the company did not provide details about the number of affected customers or the amount of the damage.
The new development lies in the official confirmation of the security incident and the specification that the attackers used a legitimate government domain to make the fraudulent requests. The discrepancy between the apparently official address and the unauthorized nature of the requests enabled the exposure of personal and financial data.
Sources
Latest News
22:25
22:13
22:07
21:39
21:27
See more news