Revolut confirmed it shared sensitive customer information with an unauthorized party after accepting fraudulent “government” information requests sent from an email address on a legitimate government domain. The company says this was an external impersonation scam (not a system hack) and that customer funds were not affected, but exposed data could enable follow-on identity fraud and scams.
Key findings
- Revolut disclosed sensitive customer records to an unauthorized party after accepting fraudulent information requests.
- The requests were sent “from an email address on a legitimate government agency domain,” leveraging trust in official domains.
- Revolut described the incident as “an external impersonation scam, not an intrusion into its systems,” and said “customer funds were not affected.”
- Exposed data types included identity/contact details, copies of IDs (passport/driver’s license), verification selfies, and account statements/transaction histories.
- Revolut says only a “limited” or “very limited” number of customers were affected and those customers are being contacted directly.
Who’s being targeted
- Commonly targeted roles: Legal, Compliance, Privacy/Data Protection, Customer Support/Operations, Fraud/Financial Crime team.
- Affected industries: Financial services / digital banking.
- Attack channels: email.
- Impersonated: Government agency (unspecified).
Awareness takeaways
- Treat unexpected ‘official’ requests for sensitive data as suspicious and verify using trusted, independent channels before responding.
- Have a clear process for responding to law-enforcement/government data requests, including verification steps and escalation to Legal/Privacy.
- Prepare customers and front-line teams for follow-on scams after data exposure (account ‘security’ messages, reverse-transfer scams, document ‘replacement’ requests).
Red flags to watch for
- Unusual or unexpected request for sensitive customer records via email, even if the sender domain appears official
- Pressure to comply without secondary verification or a known case/reference number
- Request scope includes high-risk documents (IDs, selfies, transaction history) beyond what is necessary
Read the video transcript
Revolut just handed real customer data to a scammer… from what looked like a real government email. The scammer emailed from a legitimate government domain, asked for IDs, selfies, and transaction history, and Revolut sent it, no system hack, just trust in the email. Here’s the trap: the email feels urgent and official, but it’s unexpected, has no clear case number, and demands way more data than a normal request. If you get an ‘official’ email asking for customer records, stop. Don’t reply from the email, call or message the agency using our approved contact list and verify first.