Revolut says it handed over sensitive customer identity and financial data after receiving what looked like a legitimate government information request. The email came from inside a real government agency’s email domain and passed authentication checks, so staff processed it before later discovering it was fraudulent. The exposed data included ID documents, verification selfies, account statements (including IBAN), and transaction history including Bitcoin.
How the attack worked
An attacker either created a rogue account within an official government agency's email domain or compromised an existing one, then used that account to submit what looked like a legitimate customer data request. Because the message carried valid domain authentication credentials, it passed automated authenticity checks and was processed under the reasonable belief that it was a genuine government request. Staff released a substantial data package in response, including identity documents, verification selfies, account statements with IBAN details, and full transaction history including Bitcoin.
Why it succeeded
The request exploited a gap between technical email authentication and actual authorization. Domain authentication confirms that a message originated from infrastructure tied to a domain, but it does not confirm that the specific sender or mailbox is authorized to make the request being made. Relying mainly on email authentication allowed an attacker with access to a government domain to bypass checks and obtain sensitive customer data without triggering a manual verification step before the data was sent.
What to watch for
- Requests for a full KYC package (ID documents plus verification selfie) bundled with account statements and transaction history in a single ask.
- Legal or government-style requests that arrive only by email with no independent verification channel offered or used.
- Unusually broad or specific asks that suggest the requester already knows details about particular customers, which may indicate targeting of high-net-worth individuals.
- Any data request where the only proof of legitimacy offered is a technically valid sending domain.
How to build resistance
Compliance, legal, AML/KYC operations, and fraud teams should treat valid domain authentication as necessary but not sufficient proof of a legitimate request. Before releasing customer data in response to a government or legal request, staff should independently verify the request through a known contact channel for the requesting agency, separate from the email that made the request. Unusually broad data requests, especially those combining identity documents, financial statements, and transaction histories, should be escalated for additional review rather than fulfilled on receipt. Building this verification step into standard procedure reduces the risk that a compromised or rogue account inside a trusted domain can be used to extract sensitive customer records.
Key findings
- A fraudulent customer-data request was sent from an unauthorized mailbox that used a real government agency’s official email domain infrastructure.
- The message “carried valid domain authentication credentials,” so it passed email authenticity checks and was processed as if it were a real government request.
- Exposed data included identity/contact information, copies of passports/driver’s licenses, verification selfies, account statements (including IBAN), and full transaction histories including Bitcoin.
- Revolut later discovered the fraud only after independently contacting the government agency to confirm the request, and the agency said it did not make the request.
- A crypto security researcher assessed the operation appeared targeted at high-net-worth users.
Who’s being targeted
- Commonly targeted roles: Compliance, Legal, AML/KYC Operations, Privacy/Data Protection, Fraud Operations, Customer Support (high-value customers), Security/Incident Response.
- Affected industries: Fintech, Banking, Cryptocurrency/Blockchain services, Financial services compliance (KYC/AML).
- Attack channels: email.
- Impersonated: Government agency (official government email domain), Government agency investigator/authority.
Red flags to watch for
- Request is made purely over email and relies on “valid domain authentication credentials” as proof, without an out-of-band verification step.
- Unusual scope of data requested (e.g., full KYC package plus account statements/transaction history).
- Sender mailbox is unauthorized even though it uses an official government domain (possible compromised/rogue account).
- Highly sensitive combination of data requested (ID docs + selfie + IBAN/account statements + crypto transactions).
- Request appears tailored toward wealthy individuals rather than a broad legitimate inquiry.
- Verification happens only after fulfillment instead of before.
Frequently asked questions
How did the fraudulent request bypass Revolut's checks?
The email carried valid domain authentication credentials because it was sent from an unauthorized mailbox within a real government agency's official domain, so it passed authenticity checks and was processed as a legitimate request.
What customer data was exposed in this incident?
The exposed data included identity and contact details, copies of passports and driver's licenses, verification selfies, account statements including IBAN, and full transaction histories including Bitcoin.
How was the fraud discovered?
Revolut discovered the fraud only after independently contacting the government agency to verify the request, at which point the agency confirmed it had not made it.
Who appears to have been targeted in this attack?
A crypto security researcher assessed that the operation appeared to be targeted at high-net-worth users.
Read the video transcript
Revolut got a government email, checked the domain, it passed all the tests… and they still sent customer passports and Bitcoin history to a fraudster. The trick? The attacker used an unauthorized mailbox inside a real government email domain. It carried valid authentication, so staff believed it was a lawful request and handed over full KYC packs and transaction histories. Here’s the scary part: everything looked fine until Revolut later phoned the agency and heard, ‘We never sent that.’ By then, high‑net‑worth customers’ IDs, selfies, IBANs, and Bitcoin histories were already gone. Your move: if an email asks for a full KYC pack plus account or crypto history, stop. Independently call or portal‑message the supposed authority using a known number before you send a single file.