Revolut confirms customer data breach through fake government requests
Revolut confirms customer data breach through fake government requests
Revolut 确认因伪造政府请求导致客户数据泄露
British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. 英国金融科技公司 Revolut 确认,在收到来自合法政府机构电子邮件域名的欺诈性请求后,该公司向未经授权的第三方披露了敏感的客户信息。
The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. 根据 TechCrunch 查看的一份发送给受影响客户的通知显示,泄露的数据包括客户的身份和联系方式(如出生日期、邮寄地址、电子邮件地址和电话号码),以及身份证明文件副本(包括护照和驾照)。
The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification. A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. 该公司在通知中表示,泄露的数据可能还包括验证自拍照、账户对账单和交易记录。Revolut 发言人向 TechCrunch 证实,受影响的客户数量“有限”,并表示公司已直接联系了这些客户。
Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved. 然而,Revolut 并未披露受影响个人的确切数量。该公司也没有回答该事件是否仅限于特定市场,并拒绝透露涉及的政府机构名称。
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said. 该发言人表示:“Revolut 最近发现了一起复杂的外部冒充诈骗案,未经授权的第三方利用合法的政府机构域名电子邮件提交了欺诈性的信息请求。”
Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the relevant government agency, law enforcement, and relevant regulators, adding, “Revolut systems and customer funds are unaffected.” Revolut 告诉 TechCrunch,在发现该未经授权第三方的诈骗行为后,他们封锁了该电子邮件地址,并通知了相关政府机构、执法部门和相关监管机构,并补充道:“Revolut 的系统和客户资金未受影响。”
London-based Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries, per its website. The fintech recently expanded its presence in markets including India, Mexico, France, and the UAE. 据其官网显示,总部位于伦敦的 Revolut 在全球拥有超过 8000 万客户,并在 30 多个国家以银行身份运营。这家金融科技公司最近扩大了在印度、墨西哥、法国和阿联酋等市场的业务。
Moreover, earlier this month, the U.S. Office of the Comptroller of the Currency granted a conditional approval to Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027. 此外,本月初,美国货币监理署(OCC)批准了 Revolut 在美国设立国家银行的附带条件许可,该公司预计将于 2027 年上半年启动该业务。
Well-known crypto security researcher ZachXBT posted about Revolut’s email to its affected customers late on Friday. The researcher said the incident appeared to have been targeted at high net worth users. 知名加密安全研究员 ZachXBT 于周五晚些时候发布了关于 Revolut 发给受影响客户的邮件的相关信息。该研究员表示,此次事件似乎针对的是高净值用户。
The incident comes as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November. The fintech has also been expanding its banking footprint in Europe and globally, securing banking licenses in France and the UK in recent months. 此次事件发生之际,据报道 Revolut 正在权衡潜在的上市计划,其估值可能高达 2000 亿美元,高于 11 月份 750 亿美元的私募估值。这家金融科技公司近期也在扩大其在欧洲及全球的银行业务版图,并在近几个月获得了法国和英国的银行牌照。