Revolut to Cover ID Replacement Costs After Customer Data…
By Abdelaziz Fathi

AI summary of the source article
Revolut announced it will pay to replace compromised identity documents for 680 customers whose sensitive records were handed to hackers posing as Italian authorities. The attackers exploited a compromised government email account from the Prefecture of Reggio Calabria to submit fraudulent information requests. Records exposed included identity documents, selfies, IBANs, and transaction histories. Béatrice Cossa-Dumurgier, Revolut's CEO for Western Europe, confirmed the remediation effort while maintaining that Revolut's internal technology systems were not breached. The UK Information Commissioner's Office is investigating the incident as Revolut faces scrutiny over whether its procedural verification controls for handling official data requests were adequate.
Why it matters
The incident highlights procedural compliance and verification vulnerabilities for rapidly growing fintechs responding to official law enforcement data requests.
Key facts
- Revolut will pay to replace compromised identity documents for 680 affected customers, including 55 in France and eight in Italy.
- Attackers obtained sensitive data by submitting fraudulent requests through a compromised email account associated with the Prefecture of Reggio Calabria.
- The UK Information Commissioner's Office opened an investigation into the incident, while Revolut stated its internal systems were not breached.