Revolut confirmed that an attacker impersonated a government agency using an email address on that agency’s real domain to obtain sensitive customer records. Revolut says only a limited number of customers were affected and that customer funds and Revolut systems were not accessed.
How the Attack Worked
An attacker impersonated a government agency by using an email address on that agency's real domain. This gave the request an appearance of legitimacy that likely bypassed the usual skepticism reserved for external inquiries. Using this pretext, the attacker requested customer records from Revolut, framing it as an official regulatory or law enforcement inquiry that required urgent action.
According to Revolut, the data exposed to the attacker included contact details, dates of birth, and copies of identity documents such as passports and driving licences. Verification selfies, account statements, and transaction histories may also have been included. A third party separately claimed that additional fields, such as IBANs and bitcoin transaction history, were exposed, and assessed the targeting as focused on high-net-worth users.
Why It Succeeded
The core weakness exploited here was trust in domain-level legitimacy. Because the request came from an address on the agency's actual domain, staff handling the inquiry had reduced reason to suspect impersonation through typical technical indicators like spoofed domains or lookalike addresses. Combined with urgency and the appearance of an official process, this created pressure to respond quickly rather than pause for independent verification.
The request also asked for a broad scope of sensitive data, including identity documents and financial details, well beyond what a routine or narrowly scoped inquiry might need. Without a step to confirm the request through a secondary, trusted channel, this broad ask was fulfilled.
What To Watch For
- Requests for customer data that arrive by email alone, without a secondary verification step such as a documented legal process or a callback to a known number
- Urgency or pressure to release sensitive records quickly
- Requests for unusually broad data, such as full identity documents, statements, or transaction histories, rather than narrowly scoped information
- Government or regulatory requests that skip formal service channels typically used for legal processes
How To Build Resistance
Organizations handling sensitive customer data should treat any request, even one from an apparently legitimate government domain, as unverified until confirmed through an independent channel such as a known phone number or official portal. Data sharing should follow a minimum-necessary principle: identity documents, statements, and transaction histories should only be sent when a request is fully validated and clearly requires that scope.
Compliance, legal, and privacy teams should have a fast internal escalation path for external data requests, along with a clear process to block and report suspicious senders immediately. Revolut said it blocked the sender's address upon detecting the scheme and notified the relevant government agency, law enforcement, data protection authorities, and financial regulators, illustrating the kind of rapid response and multi-party reporting that limits further exposure once impersonation is identified.
Key findings
- The attacker impersonated a government agency and used an email address on that agency’s domain to obtain Revolut customer records.
- Revolut notified affected customers that data exposed included contact details, dates of birth, and copies of identity documents; additional financial identifiers and transaction details may also have been included.
- A third party (ZachXBT) claimed additional exposed fields (e.g., IBANs and bitcoin transaction history) and assessed the targeting as focused on high-net-worth users.
- Revolut says it blocked the sender address and reported the incident to the relevant agency, law enforcement, regulators, and data protection authorities.
- Revolut stated its systems and customer funds were not compromised.
Who’s being targeted
- Commonly targeted roles: Compliance, Legal, Privacy/Data Protection, Customer Support, Operations.
- Affected industries: Financial services, Fintech, Banking.
- Attack channels: email.
- Impersonated: Government agency (unspecified).
Red flags to watch for
- Unexpected urgency and pressure to release sensitive records quickly
- Request for unusually broad data (e.g., identity documents, statements, transaction histories)
- Request relies on email alone without secondary verification or formal service channels
Frequently asked questions
How did the attacker obtain Revolut customer data?
An attacker impersonated a government agency using an email address on that agency's actual domain, and used this to request and obtain sensitive customer records from Revolut.
What customer data was exposed in the Revolut incident?
Revolut told affected customers that exposed data included contact details, dates of birth, and copies of identity documents, with financial identifiers and transaction details possibly also included.
Were Revolut's systems or customer funds compromised?
No, Revolut stated that its systems and customer funds were not accessed or compromised in this incident.
What should organizations do to prevent similar attacks?
Treat data requests from government-looking domains as untrusted until verified through an independent channel, apply minimum-necessary data sharing, and maintain a fast escalation path for suspicious requests.
Read the video transcript
Imagine this lands in your inbox: “Urgent request for customer records – official government inquiry.” That’s exactly how Revolut got tricked. Someone impersonated a government agency, used an email on that agency’s real domain, and got Revolut to hand over customer records, IDs, contact details, even transaction history for some high‑net‑worth users. Here’s the trap: it felt routine, regulator asking for info, but the red flags were there: unexpected urgency, a demand for broad data like identity documents and full transaction histories, and everything handled over plain email. If any “government” email asks for customer records, stop and escalate it to Compliance or Legal using our internal process, do not send a single file back by email.