Online bank Revolut has revealed that it gave out sensitive personal and financial information of an undisclosed number of its customers in response to a fake government request.
The information that was handed over to an “unauthorized third party” reportedly includes names, dates of birth, occupations, addresses, phone numbers, account numbers, transaction histories (including Bitcoin), and even copies of government-issued IDs and onboarding verification selfies.
Revolut claims that derived biometric face data was not.
The company said that the data was handed over in response to an email that came from a real government agency’s domain, but was not actually sent or authorized by that agency.
The email passed several authentication checks (SPF, DKIM, and DMARC) that are designed to establish the authenticity of a message’s origin and integrity, but do not verify the legitimacy of the legal request itself.
Revolut said that it complied with the request “under the reasonable belief that it was an authentic government agency request” – and only later found out that it was not.
Revolut said it later realized its mistake, blocked the email address, and reported the incident to the relevant authorities.
Revolut said that only a “limited” number of its customers were affected by the data leak, and that the company’s systems were not hacked, nor was any money stolen.
The story broke on September 11 when Revolut customers started receiving an email notice about a data leak, and the news was picked up by media outlets the following day.