Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Revolut sent customer passports to an impostor. The email address was genuine.

An unauthorised third party used a legitimate government agency domain email address to request customer information while posing as that agency, SecurityWeek reported.

ERP LEADERS news desk · · First reported by SecurityWeek · Edition no. 8
Photo: Boubloub/Wikimedia, CC0 · original

Revolut treated those requests as authentic.

Revolut's statement, quoted by SecurityWeek: "Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information."

SecurityWeek reports that the disclosed data included names, addresses and dates of birth. Copies of driving licences and passports were released, along with verification selfies. The disclosure also covered IBANs, account statements and full transaction history.

Revolut says the scale was limited: "Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support." The company has not published a number of affected users.

Revolut says its own systems were untouched. A request arrived from a trusted domain, and a process approved it.

Who in your company can release customer records on an email alone?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story
Revolut

Every story here is open to read. The ERP LEADERS brief goes one step further.

One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01