en
Back to the list

Watch Out: A Cryptocurrency Exchange Accidentally Shared User Information with Hackers

source-logo  en.bitcoinsistemi.com 18 m
image

Blockchain researcher ZachXBT suggests that fintech company Revolut may have shared some users’ personal data with third parties by mistaking a fake government agency request for a real one. According to information shared on ZachXBT’s personal channel, the incident began when Revolut received a customer information request that appeared to come from a legitimate government agency and used the agency’s official email domain.

Allegedly, the email in question was accepted as genuine by Revolut because it contained valid domain verification information. As a result of the company failing to detect that the request was fraudulent, some user information may have been accessed or shared in response to the request.

Potentially affected data includes users’ first and last names, dates of birth, occupations, addresses, email addresses, and phone numbers, as well as copies of passports or driver’s licenses, selfies taken during identity verification, account statements, IBAN information, withdrawal records, and extensive transaction histories including Bitcoin transactions. Revolut’s security notice to users stated that biometric facial telemetry data was not affected by the incident.

ZachXBT noted that while the incident appears limited in scale at present, it may have specifically targeted high-asset users. According to the statement, multiple Revolut users recently received security alerts related to the incident.

*This is not investment advice.

en.bitcoinsistemi.com