Revolut sent customer passports to an impostor. The email address was genuine.
An unauthorised third party used a legitimate government agency domain email address to request customer information while posing as that agency, SecurityWeek reported.
Revolut treated those requests as authentic.
Revolut's statement, quoted by SecurityWeek: "Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information."
SecurityWeek reports that the disclosed data included names, addresses and dates of birth. Copies of driving licences and passports were released, along with verification selfies. The disclosure also covered IBANs, account statements and full transaction history.
Revolut says the scale was limited: "Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support." The company has not published a number of affected users.
Revolut says its own systems were untouched. A request arrived from a trusted domain, and a process approved it.
Who in your company can release customer records on an email alone?
Sources
Every story here is open to read. The ERP LEADERS brief goes one step further.
One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.
Welcome back. · Issue 01
