Investing.com -- Revolut has contacted 680 customers following a data breach in which the fintech company handed over sensitive personal information to cybercriminals posing as government officials.
The breach occurred after a hacker used a legitimate government email address to send a fraudulent request for private customer information. Revolut complied with the request and provided sensitive data including passport details, bank account numbers, home addresses, verification pictures, identity cards and Bitcoin activity records.
Hackers claiming responsibility for the incident are threatening to release the information publicly unless Revolut pays a ransom.
Britain's Information Commissioner's Office said Monday it was investigating the incident after Revolut reported itself to the watchdog days earlier.
Revolut spent the weekend responding to the breach. The company said it "immediately blocked the address" after detecting the issue and notified regulators and affected customers.
Mark Karpelès, former chief executive of Mt Gox, was among the affected customers. He received an email from Revolut at 5:25 a.m. on September 12 alerting him to the scam and warning that his data may be at risk. Karpelès said he believes Revolut should not have shared the information regardless of whether the email came from a verified government address.
Related articles