Revolut confirmed it disclosed sensitive customer information after fraudsters sent “emergency” information requests from a legitimate government email domain. The attackers appear to have targeted high-net-worth customers, including people involved in crypto, and attempted to extort Revolut to prevent broader data release.
How the attack worked
Fraudsters submitted what looked like a legitimate emergency data request (EDI) using a real government agency email domain. The pretext relied on urgency: the request demanded immediate disclosure of customer information, framing the situation as time-critical to discourage standard verification steps. Because the sender's domain appeared authentic, the request bypassed normal scrutiny that a compliance or legal team might apply to an unfamiliar sender.
According to reporting, the attackers appeared to focus on high-net-worth customers, including individuals involved in crypto asset businesses. The data obtained reportedly included identity documents, verification selfies, bank statements, IBANs, withdrawal records, and transaction history including Bitcoin activity, a scope far broader than a routine, narrowly-defined law enforcement request would typically require.
Why it succeeded
The core failure point was trust placed in the sending domain rather than the legitimacy of the request itself. A legitimate-looking government email address created a false sense of assurance, even though the underlying access may have been unauthorised or compromised. This mirrors a pattern seen in prior incidents where criminals used compromised law enforcement accounts to submit forged emergency data requests to major tech companies, exploiting the same urgency and domain-trust dynamic.
The emergency framing itself is a well-known social engineering lever: it pressures staff to act quickly and skip escalation or independent verification, especially when the requester claims lives or investigations are at stake.
What to watch for
- Requests labeled "emergency," "urgent," or "immediate disclosure required" for customer records
- Broad requests for complete identity and financial data rather than narrowly scoped information
- Government-domain senders requesting expedited handling outside normal legal channels
- Any request that discourages a callback or independent verification step
How to build resistance
Organizations handling sensitive customer data should treat every emergency data request as high-risk by default. Practical steps include:
- Requiring independent verification (a callback to a known, previously validated contact number) before releasing any data under an emergency request
- Escalating any request for broad identity or financial records to privacy and legal leadership rather than allowing frontline teams to respond directly
- Recognizing that a legitimate-looking sending domain does not guarantee the request itself is authorized, since accounts can be compromised or misused
- Maintaining a predefined incident playbook for extortion attempts following data exposure, covering communication with regulators and law enforcement
These measures target the specific mechanism this incident relied on: urgency plus domain trust overriding standard verification. Building friction into emergency request handling, without slowing genuinely legitimate law enforcement cooperation, is the practical defense against this technique.
Key findings
- Fraudsters used a legitimate government agency email domain to submit fraudulent “emergency” requests for customer information.
- The perpetrators appeared to focus on high-net-worth individuals, including those involved in crypto asset businesses.
- Exposed data (per customer notices shared by impacted individuals) included identity documents and financial activity such as bank statements, IBANs, withdrawal records, and transaction history including Bitcoin activity.
- Attackers allegedly attempted to extort Revolut to prevent customer data from being released.
- This mirrors prior tactics where criminals used compromised law-enforcement accounts and forged emergency data requests to obtain data from major tech firms.
Who’s being targeted
- Commonly targeted roles: Legal, Compliance, Privacy/Data Protection, Customer Support, Fraud/Trust & Safety, Security Operations, Executive leadership (incident decision-makers).
- Affected industries: Financial services / fintech, Cryptocurrency / digital assets.
- Attack channels: email.
- Impersonated: Government agency (using a legitimate government domain email account).
Red flags to watch for
- Request relies on urgency/emergency framing to bypass normal verification steps
- Sender uses a legitimate-looking government domain but the request is unauthorised
- Request seeks unusually broad/complete customer data (IDs, selfies, bank statements, transaction history)
Frequently asked questions
What is an emergency data request attack?
It is when attackers impersonate a government agency or law enforcement using urgency framing to convince a company to bypass normal verification and release customer data immediately.
How did fraudsters access a legitimate government email domain?
The JSON does not specify how the domain was obtained, only that an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information.
What kind of data was exposed in this incident?
Exposed data reportedly included birth dates, addresses, phone numbers, passport and driver's license copies, verification selfies, bank statements, IBANs, withdrawal records, and transaction histories including Bitcoin activity.
Who was targeted in this scheme?
The perpetrators appeared to focus on high-net-worth individuals, including those involved in crypto asset businesses.
Read the video transcript
Revolut leaked customer data because of one email that looked like it came from a real government address. Fraudsters used a legitimate government agency email to send fake “emergency” data requests, then tried to extort Revolut after getting IDs, bank statements, even Bitcoin transaction history. Here’s the trap: the domain looked real, the tone was urgent, and the request asked for everything at once, perfect recipe to skip normal checks and just send the data. If you ever get an “emergency” request for customer data, even from a real-looking government email, stop and call back using our approved contacts before you send anything.