Revolut Customer Data Exposed in Italian Government Domain Phishing Scam

Some Revolut customers' personal information and financial transaction records were improperly disclosed to third parties via a fraudulent email request using an Italian government agency domain. The exposed data included copies of identity documents, selfie verification photos, IBAN numbers, withdrawal records, full transaction histories, and Bitcoin transaction details. Revolut has labeled the incident as a 'sophisticated external impersonation fraud,' according to Crypto Briefing's report on December 12th. The company blocked the email account in question and notified relevant authorities, stating that customer funds and internal systems were unaffected. Revolut contacted affected customers directly but did not disclose the number of victims or which government agency was impersonated. The incident raised concerns about vulnerabilities in verification procedures for official requests that passed through legitimate government domain emails as part of urgent information request protocols.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 레볼루트 고객정보, 이탈리아 정부 도메인 사기 요청에 노출