Revolut is a digital banking services firm that operates as a fully licensed bank in 30 countries worldwide, including Australia since 21 July this year. It is best known for its multi-currency travel cards that allow customers to access easy spending when travelling abroad.
The company said it mistakenly handed over customer data to an unauthorised third party after it received fake emails from an official government agency’s email domain.
“Revolut received a request for customer information that appeared to come from a legitimate government agency,” the company said.
“The request came from an unauthorised email account sent directly using the official government agency’s email domain.
“As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.”
As per communications from the bank, data included in the breach included names, birth dates, occupations, email addresses, phone numbers, postal addresses, copies of identity documents and facial verification images, as well as financial data, including account statements, full transaction history, including bitcoin, withdrawal records, IBAN, account status, wallet reference numbers and account opening dates. No biometric facial telemetry data was impacted.
Revolut said it blocked the email address upon becoming aware of the scam and notified relevant regulators, government agencies, and law enforcement.
The threat actor behind the incident has not yet been identified.
The incident comes as Revolut is eyeing a public valuation of as much as US$200 billion, a significant climb from its private valuation of US$75 billion last November.
Alongside Australia, the company has also secured banking licenses in France and the UK in previous months this year, and expects to fully launch bank services in the USA next year.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.