A person posing as a government agency used an email address on that agency’s real domain to obtain sensitive customer records from Revolut. The same weekly roundup also describes a fake antivirus renewal web page impersonating Avast, telling victims their subscription renewed for €129.99 and prompting them to act.
How the attack worked
A person impersonating a government agency used an email address on that agency's real domain to request sensitive customer records. Because the email came from an authentic domain, it carried the appearance of legitimacy, and Revolut confirmed the incident. This case illustrates how domain-level authenticity can be misused: owning or accessing a real government email address is enough to make a request look credible, even when the actual sender has no authorization to make it.
Why it succeeded
The request relied on implied authority rather than a verified process. Customer support, compliance, and fraud teams are trained to respond to legitimate government inquiries, and an email from a real agency domain short-circuits the usual skepticism. Without a separate verification step, such as calling a published agency contact or checking an internal escalation list, a convincing domain and an authoritative tone can be enough to move sensitive data.
A related example from the same period shows a different but connected pattern: a fake Avast renewal page told visitors their subscription had renewed for €129.99 and would renew again in February. Researchers noted the page was more polished than typical scam sites, suggesting AI tools are helping less skilled scammers build convincing fakes. Both cases show that visual or domain-level polish is not a reliable signal of legitimacy.
What to watch for
- Requests for sensitive customer data based solely on an email, without a secondary verification step
- Reliance on sender domain trust instead of a documented, verified request process
- Urgency or authority-based pressure from an external party asking for records or payment action
- Unexpected billing or renewal notices that push a quick response
- Pages or messages that look unusually professional; polish alone does not confirm authenticity
How to build resistance
Organizations handling customer data, especially in banking and fintech, should require independent verification for any external request involving sensitive records, regardless of how authoritative the sender domain appears. This means confirming requests through officially published contact channels rather than replying to the original email.
Employees across all teams should also be trained to treat unexpected renewal or billing messages with the same skepticism, using vendor contact information they look up themselves rather than links or numbers provided in the message. Building this habit into standard workflows, rather than relying on individual judgment in the moment, reduces the chance that a well-crafted impersonation attempt succeeds. As scam pages become more polished with the help of AI tools, verification processes matter more than visual trust signals.
Key findings
- Revolut said a party impersonating a government agency used an email address on that agency’s domain to obtain sensitive customer records.
- A scam web page impersonating Avast told users their Avast Premium Security subscription had renewed for €129.99 and would renew again in February.
- Attackers also abused a trusted online presence by compromising the verified official HBO Max Reddit account and using it for a malvertising campaign (ClickFix).
Who’s being targeted
- Commonly targeted roles: Customer Support, Compliance, Fraud/Investigations, Finance, All Employees, IT Helpdesk.
- Affected industries: Banking/Fintech, Consumer/retail banking customers, Media/Entertainment (social account hijack context).
- Attack channels: email, website.
- Impersonated: A government agency (using that agency’s real email domain), Avast.
Red flags to watch for
- Request for sensitive customer data based solely on an email
- Relies on sender domain trust rather than a verified request process
- Unusual urgency or authority-based pressure from an external party
- Unexpected renewal charge and pressure to act
- Brand impersonation (Avast) on an untrusted page
- High-pressure billing language designed to trigger panic clicks/calls
Frequently asked questions
How did attackers get Revolut to share customer data?
Someone impersonating a government agency used an email address on that agency's actual domain to request and obtain sensitive customer records from Revolut.
Why did the sender's domain not guarantee legitimacy?
Using a real domain does not prove the sender is authorized to act for that agency, since domain trust alone was relied on instead of a verified request process.
What other impersonation tactic was seen in the same period?
A fake Avast renewal page told visitors their subscription had renewed for €129.99 and would renew again in February, pressuring them to act quickly.
What should employees do before responding to authority-based requests?
Verify the request through an official, independently looked-up channel rather than replying directly to the email or trusting the sender domain alone.
Read the video transcript
Someone used a real government email domain to trick Revolut into handing over sensitive customer records. The email looked official, came from that agency’s real domain, and asked for customer records. Revolut confirmed on September twelfth that they sent data based only on that email. Same playbook on the web: a polished fake Avast page says your Avast Premium Security just renewed for €129.99, covers five devices, and will renew again in February, pushing you to click or call fast. Here’s the move: if any email or web page asks for data or money, ignore the link and start your own contact, use our official process or the vendor’s site you look up yourself.