In an email to customers, trading platform Stake said that an incident at US third-party firm DriveWealth led to personal data belonging to Stake customers being exposed.
“We are sincerely sorry for any concern this news has caused and apologise for any inconvenience caused as a result of the incident,” the company said.
“Stake takes the security of personal information seriously and has been working closely with DriveWealth to understand the impact of the incident.”
According to the email, compromised data includes names, email addresses, phone numbers, tax status and country and postal addresses.
However, Stake confirmed that tax file numbers, bank accounts, trading accounts and portfolios were unaffected, with no evidence of unauthorised trading, withdrawals or transfers.
The cyber attack on DriveWealth also impacted Revolut customers worldwide, including the US, the UK, the EEA and Australia.
“DriveWealth recently informed us that an unauthorised party accessed customer data held on its systems. Revolut’s own systems, app infrastructure, and core databases were not accessed or affected in any way. All Revolut customer funds and investments remain completely safe,” the company said.
The threat actor behind the incident is yet to be identified.
This marks the second incident for Revolut this month after it mistakenly handed over customer data to an unauthorised third party after it received fake emails from an official government agency’s email domain, it disclosed earlier this month.
“Revolut received a request for customer information that appeared to come from a legitimate government agency,” the company said regarding the incident that took place on 21 July.
“The request came from an unauthorised email account sent directly using the official government agency’s email domain.
“As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.”
As per communications from the bank, data included in the breach included names, birth dates, occupations, email addresses, phone numbers, postal addresses, copies of identity documents and facial verification images, as well as financial data including account statements, full transaction history including bitcoin, withdrawal records, IBAN, account status, wallet reference numbers and account opening dates. No biometric facial telemetry data was impacted.
Revolut said it blocked the email address upon becoming aware of the scam and notified relevant regulators, government agencies and law enforcement.
This article was originally published on Banking Daily.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.