Revolut 确认发生客户数据泄露,起因为伪造的政府请求。
Revolut confirms customer data breach through fake government requests

原始链接: https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/

英国金融科技公司 Revolut 证实,在遭遇一起复杂的冒充诈骗后,公司发生了涉及客户敏感信息的数据泄露事件。该公司报告称,一名未经授权的第三方利用一个合法的政府机构邮箱域名提交了欺诈性请求,导致客户数据外泄。 泄露的信息包括姓名、出生日期、联系方式、身份证明文件(护照和驾照),在某些情况下还包括身份验证自拍照和交易记录。Revolut 表示,受到影响的客户数量“有限”,且所有受影响的人员均已收到通知。该公司强调,其内部系统和客户资金仍然安全。 该公司已封锁了该欺诈电子邮件地址,并将此事报告给了执法部门和相关监管机构。虽然 Revolut 未说明受影响用户的具体数量或受影响地区,但安全研究员 ZachXBT 指出,此次攻击的目标可能主要是高净值人群。 这家总部位于伦敦的公司在全球拥有超过 8000 万客户,此次泄露事件正值该公司继续寻求国际银行牌照并探索潜在上市之际。

Hacker News 最新 | 过往 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 Revolut 确认因伪造政府请求导致客户数据泄露 (techcrunch.com) 20 积分,tdrz 发布于 1 小时前 | 隐藏 | 过往 | 收藏 | 4 条评论 hndhyc0bdt 7 分钟前 | 下一条 [-] 我曾负责过一段时间的执法部门(LE)请求处理工作,整个流程全是来自形似 .gov 邮箱的 PDF 文件。我们唯一的有效核查手段就是通过我们自己查到的电话号码打回去,而不是信头(letterhead)上提供的那个。 回复 cassianoleal 9 分钟前 | 上一条 | 下一条 [-] > 数据可能还包括验证自拍 他们为什么要留存这些东西? 回复 dotancohen 8 分钟前 | 父评论 | 下一条 [-] 为了应付官司,以防万一。 回复 hrpnk 11 分钟前 | 上一条 | 下一条 [-] 即使触发请求的是伪造信息,为什么政府没有提供一个用于接收数据的安全通道?难道这个通道也被攻破了吗? 回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请加入 YC | 联系 搜索:
相关文章

原文

British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.

The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.

A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.

Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the relevant government agency, law enforcement, and relevant regulators, adding, “Revolut systems and customer funds are unaffected.”

London-based Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries, per its website. The fintech recently expanded its presence in markets including India, Mexico, France, and the UAE. Moreover, earlier this month, the U.S. Office of the Comptroller of the Currency granted a conditional approval to Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027.

Well-known crypto security researcher ZachXBT posted about Revolut’s email to its affected customers late on Friday. The researcher said the incident appeared to have been targeted at high net worth users.

The incident comes as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November. The fintech has also been expanding its banking footprint in Europe and globally, securing banking licenses in France and the UK in recent months.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

联系我们 contact @ memedata.com