Revolut says it disclosed sensitive customer information after receiving fraudulent information requests that appeared to come from a real government agency email domain. The company framed it as a sophisticated impersonation scam, not a technical break-in, showing how “legitimate-looking” requests can still be malicious when they ask for customer data.
Key findings
- Revolut disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests.
- The requests were sent from “a legitimate government agency’s email domain,” making the outreach look authentic.
- Revolut characterized the incident as “a sophisticated impersonation scam rather than a system intrusion.”
- Exposed data included identity and contact details, dates of birth, addresses, phone numbers, and copies of identity documents; in some cases it included verification selfies, statements, and transaction histories.
- The incident highlights that authenticated-looking government-domain emails still require strict verification before releasing customer data.
Who’s being targeted
- Commonly targeted roles: Compliance, Legal, Customer Support, Trust & Safety, Privacy/Data Protection, Fraud/Risk Operations.
- Affected industries: Financial services / Fintech.
- Attack channels: email.
- Impersonated: Government agency (using a legitimate government email domain).
Awareness takeaways
- Do not treat a recognizable sender domain (even a government domain) as proof a request is legitimate, verify requests through an independent, documented process before sharing customer data.
- Train teams who handle sensitive disclosures (Compliance/Legal/Support) to recognize impersonation-based data requests as a breach risk, even when no systems are ‘hacked.’
- Apply extra scrutiny and escalation for requests seeking high-risk identity artifacts (passports, driver’s licenses, selfies) and financial records (statements/transactions).
Red flags to watch for
- The request relies on the sender’s domain reputation rather than a verified case number/process.
- High-sensitivity data requested (IDs, selfies, statements) without strong, independent verification.
- Unusual urgency or deviations from standard lawful-request workflow (e.g., submitted by email alone).
Read the video transcript
Revolut handed over customer data to a fraudster… and the email came from a real government domain. The message said, 'We are requesting sensitive customer information as part of an official government information request.' Because it looked authentic, Revolut sent IDs, selfies, statements, even transaction histories, to an unauthorized third party. Here’s the trap: the attacker didn’t hack Revolut’s systems. They exploited trust in a real government email domain. Even properly authenticated, legitimate-looking correspondence can be malicious when it asks for customer data. If an email asks for IDs, selfies, or statements, even from a government domain, stop and follow our official lawful-request process. One rule: no process, no data.