Revolut has disclosed the personal and financial information of 680 customers after an unauthorised party used an email account operating within a legitimate government agency's domain to submit fraudulent requests for private data.
The London-headquartered fintech fulfilled the requests because they appeared to come from an official government source. Reporting by Infosecurity Magazine said the emails carried valid technical authentication for the government domain and were processed by Revolut employees as standard legal-compliance requests.