BlockBeats news, September 12: On-chain detective ZachXBT stated in a post on their personal channel that Revolut is suspected of failing to identify a forged government agency information request, resulting in the leakage of some users' personally identifiable information (PII).
According to their disclosure, Revolut previously received a customer information retrieval request that appeared to come from a real government agency and was sent through the agency's official email domain. Because the email had valid domain authentication information, Revolut deemed the request genuine and responded to it.
The data potentially involved in this incident includes users' names, dates of birth, occupations, addresses, emails, and phone numbers, as well as copies of passports or driver's licenses, identity verification selfies, account statements, IBANs, withdrawal records, and complete transaction histories, including Bitcoin transaction records. In notifications sent to users, Revolut stated that no biometric facial telemetry data was leaked.
ZachXBT stated that the scale of the incident may currently be limited, but based on the circumstances, it appears to have mainly targeted high-net-worth users. Multiple Revolut users received relevant security incident notifications yesterday. Revolut officially had also previously reminded users that when encountering suspicious information, they should verify through in-app customer service and avoid providing personal or financial information.

