Threat Intelligence Brief
Curated summary with source attribution
Source: coinmarketcap.com
Threat Risk: High
Victim: Revolut customers
Incident: Unauthorized disclosure of customer PII and transaction history due to a social engineering attack.
Impact: Exposure of passports, selfies, and Bitcoin histories, increasing the risk of identity theft and targeted attacks.
Attacker: Unidentified threat actors
Analysis: The attacker leveraged a legitimate government email domain to bypass Revolut’s verification processes. This highlights a critical failure in the authentication of official data requests. The resulting leak of KYC data and transaction history creates significant privacy and security risks for the targeted users.
Recommendations: Strengthen verification protocols for all third-party and government data requests; Implement multi-step internal approvals for the export of sensitive customer PII; Advise high-value users to increase monitoring for targeted phishing and physical security threats
Source: CoinMarketCap
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source