Revolut Leaked the Data of Nearly 700 Customers to Scammers — FT

Revolut has contacted 680 customers whose data was compromised / Photo: Cristi Dangeorge / Shutterstock.com
The Financial Times has learned that the fintech company Revolut disclosed passport information, bank account numbers, and home addresses of nearly 700 customers to cybercriminals posing as government officials.
Following an initial investigation, the company contacted 680 people who, according to its information, were affected by the incident, sources told the newspaper. Revolut spent the entire weekend urgently addressing the fallout from the incident, the publication claims. Among the data obtained by the hackers were identity verification images, ID cards, and information about Bitcoin transactions, the FT reports. Hackers claiming responsibility for the incident are threatening to publish the stolen data unless Revolut pays a ransom, the newspaper added.
Among the affected customers was Mark Karpelès, the former CEO of Mt. Gox, which was once the world’s largest Bitcoin exchange, according to the FT. According to Karpeles, on the morning of September 12, he received an email from Revolut warning him about a scam and stating that his information might have been compromised. “I thought it was a scam… At first, I even felt sorry for them,” he told the Financial Times.
Now, however, Karpelès believes that Revolut should not have disclosed this information in the first place, regardless of the email’s sender address, the FT reports. Mt. Gox went bankrupt following a major cyberattack, and Karpelès was subsequently found guilty of manipulating electronic data, the publication notes.
What is known about the leak
The data breach occurred after a hacker used a legitimate email address belonging to a government agency—to which the hacker had gained access—and sent a fraudulent request from that address asking for confidential information about a number of Revolut customers. The company complied with the request and provided the attackers with sensitive data.
A Revolut spokesperson told the FT that the company recently uncovered “a sophisticated external identity-theft scam, in which an unauthorized third party used an email address in the domain of a real government agency to send fraudulent requests for information.” According to the company, after discovering the issue, it “immediately blocked the address” and notified regulators and affected customers.
"Revolut's systems and customers' funds were not affected," the company added, but declined to tell the FT how many users' data had been compromised.
On Monday, the British data protection regulator—the Information Commissioner’s Office (ICO)—confirmed to the FT that it is investigating the incident. A few days earlier, Revolut had voluntarily notified the agency of the incident.
Since its launch in 2015, Revolut has become Europe’s largest fintech company, with 80 million customers in 30 countries. The company was recently valued at $115 billion as part of a secondary stock offering.
This article was AI-translated and verified by a human editor




