The neobank handed over sensitive customer data after being deceived by a fraudulent request using the domain of a government agency.
AI-generated summary
Banks regularly receive legal requests for information from authorities. The hackers used a legitimate government domain name to fool the bank's vigilance.
Phishing attempts are increasing, but it is rare for a bank to be a victim itself. Revolut was targeted by a âsophisticated identity theft scam,â she told Le Figaro this Monday, September 14, confirming information from the specialized site French Breaches. Deceived by what it thought was a legal request for customer information by a public administration, the bank passed personal information and sensitive documents to the hackers.
Like all banks, Revolut is regularly asked for information about its customers by law enforcement or administrations, as part of legal procedures. The hackers allegedly used âan email with the real domain name of a government agency,â making the request unsuspected because it came from a legitimate address. The neobank, however, ended up detecting this fraudulent request for information and âimmediately blocked the address and alerted the government agency concernedâ (whose name is not specified) as well as the police.
Revolut indicated that a âlimited numberâ of its customers are affected, without further details, and ensures that they have been warned. The bank also did not detail the data transmitted, but some of the customers concerned shared the screenshot of the email received on social networks. Would thus be likely to have been transmitted to pirates, depending on the requests, the first and last names, date of birth, profession, postal address, email address or even telephone number. But also very sensitive data such as the copy of identity documents and the verification selfie provided when opening the account, as well as financial data such as IBAN, account opening date, transaction history, etc.
Customers concerned and notified by email are invited to exercise great caution. The information obtained by hackers could allow them to set up particularly elaborate phishing attempts or even to impersonate victims. Especially since all the data in the hackers' possession is so-called KYC data (for âknow your customerâ), that allows a bank to authenticate its customer during an exchange.
Accounts specializing in tracking cyberattacks have published screenshots on social networks of a Telegram channel in which hackers allegedly demand a ransom from Revolut. In the channel, several documents (selfies and identity papers) are shared as proof of possession of the stolen data, even if their authenticity and the link with the theft concerning the bank remain to be demonstrated at this stage. On

A pregnant woman and her two-year-old son died in a car fire on the A13 in Yvelines. At the same time, a TER derailment left 44 injured in Seine-Maritime.

Almost daily arrests of drone operators take place at the Aix-en-Provence penitentiary center to deliver drugs and phones to prisoners linked to drug trafficking, according to Ofast.

A pregnant woman and her 2-year-old son died in a car fire on the A13 in Yvelines. Furthermore, a woman was stabbed for her handbag in Issy-les-Moulineaux, leading to the arrest of a suspect.

Opening in Paris of the appeal trial of two relatives of the attacker of the TrĂšbes and Carcassonne attacks of 2018. The anti-terrorism prosecution had appealed the first instance convictions, deemed too lenient.

The police are investigating the derailment of a TER in Seine-Maritime which left 44 injured, as well as the attack on a woman stabbed for her handbag in Hauts-de-Seine.
Opening of the trial at the DrĂŽme assizes of three members of the same family for the murder of Zakaria, 15 years old, stabbed to death in April 2024 in Romans-sur-IsĂšre while he intervened in a schoolboy fight.