What happened?
Revolut, the British fintech company specializing in digital banking services, recently confirmed that it had been the victim of a data breach after a fraudster used a fake government request to deceive employees.
According to a report by TechCrunch, the attacker allegedly used an email address belonging to a legitimate government domain to lend more credibility to his requests and obtain information about certain customers.
What data was exposed?
The data in question would include, in particular:
Name, last name
Date of Birth
Address
Number
Copies of passports
Copies of driver's licenses
Selfies Used for Identity Verification
Account Information
Transaction History
Revolut states that only a limited number of customers are affected by the incident.
Revolut Responds Quickly
After discovering the fraud, Revolut says it has blocked the address used by the attacker.
The company also notified the relevant authorities to follow up on the investigation.
Revolut also states that customer funds and its systems remain secure and that the incident did not compromise users' accounts or money.
A social engineering attack
This case shows that a cyberattack does not necessarily require technical vulnerabilities. In this instance, the attacker exploited the employees’ trust by posing as a government agency. Here, instead of directly hacking into a computer system, the cybercriminal attempts to manipulate a person into voluntarily providing the desired sensitive information.
Why This Case Is Important
Financial companies (in this case, Revolut) have numerous technical safeguards in place to secure their customers’ accounts. However, no security measure is foolproof! Employees also remain a major target for cybercriminals. This incident serves as a reminder that it’s essential to know who you’re dealing with—and, above all, never to give out your personal information to just anyone!
What should customers do?
Stay extra vigilant when it comes to suspicious emails, text messages, or calls—even if they appear to be “OFFICIAL”!
And remember to avoid sharing your passwords, security codes, or banking information whenever possible in response to an unexpected request. You never know who’s behind it! If you receive a suspicious message claiming to be from Revolut or a government agency, it’s best to contact the organization directly through its official channels, such as their customer service number or email address!
Key Takeaways
This data breach highlights an often-underestimated risk: even when an IT system is properly secured, a social engineering attack can allow a fraudster to obtain the sensitive information they want!
Revolut says it has taken steps to block the attack and protect its customers!