Revolut sent identity data, contact details, and documents to hackers posing as a government agency
- Revolut fell for a spoofed government email scam, leaking sensitive customer data to attackers
- Compromised info includes IDs, selfies, account statements, IBANs, and full transaction histories
- Criminals now allegedly leaking data on Telegram, demanding 10,000 BTC (~$780M) ransom from Revolut
Digital banking platform Revolut was tricked into giving away a treasure trove of sensitive customer data to hackers, and it is now coming back to bite it.
The company told TechCrunch that it recently fell victim to a “sophisticated external impersonation scam” in which the threat actor “utilized a legitimate government agency domain email to submit fraudulent requests for information”.
In other words, the attackers either broke into, or spoofed, an email address belonging to the police, tax authorities, or other government bodies with statutory powers to demand information, and used them to demand Revolut hand over sensitive customer data.
Demanding ransom
Cybernews reports that the compromised data includes...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE