MalwareBytes

Revolut gave customer IDs and financial data to a government impostor


Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain, according to TechCrunch.

Revolut is a London-based banking and financial platform with more than 80 million customers globally, according to the company.

Revolut describes this as an external impersonation scam, not an intrusion into its systems. It also says customer funds were not affected. Revolut has not identified the government agency or disclosed its email domain.

The attacker appears to have abused the trust attached to a real government email domain to make bogus requests for customer information. Revolut detected the activity, blocked the sending address, and says it notified the relevant agency, law enforcement, data protection authorities, and financial regulators.

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”

Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:

  • Identity and contact information like dates of birth, postal address, email address, and phone number.
  • Copies of IDs such as passports and driver’s licenses.
  • Verification selfies.
  • Account statements and transaction histories.

Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.

Those customers have received or will receive an email specifying which of their personal data was disclosed:

How to stay safe

The likely consumer impact will be second-stage fraud attempts rather than immediate unauthorized transfers. Here are some guidelines to help keep your money safe:

Treat any unexpected Revolut-related contact as suspicious, especially calls, emails, WhatsApp messages, or text messages claiming you need to “secure” an account, reverse a transfer, or replace documents. Do not use links or phone numbers supplied in the message. Revolut advises ending contact with suspected scammers and contacting the company through official channels.

IDs and other exposed information could be used for identity theft. Monitor your accounts and credit reports for unfamiliar account openings or credit applications, and consider placing a fraud alert or using credit monitoring where available in your country.

If you received a notification email, check your balances, cards, beneficiaries, recent transfers, account statements, and linked devices. Report any unfamiliar activity immediately through Revolut’s secure in-app chat.

If you were involved in a data breach, read our blog Involved in a data breach? Here’s what you need to know for more recommendations. 

Pro tip: Use Malwarebytes Scam Guard to analyze any suspicious communications. It can help you determine whether a message is a scam and advise you on what to do next.


Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 



Source link