Revolut disclosed it was deceived into sharing highly sensitive customer data after receiving fraudulent information requests that appeared to come from a legitimate government email domain. The attacker’s email passed domain authentication, making it harder to detect, and the shared data may enable follow-on scams and identity fraud.
Key findings
- Revolut was fooled into disclosing customer information due to fraudulent requests that came from a legitimate government email domain.
- Exposed data reportedly included identity documents (passport/driver’s license) and facial verification images, plus bank statements and full transaction history (including Bitcoin).
- The attacker’s email had valid domain-authentication credentials, reducing the chance it would be flagged as suspicious.
- Revolut stated internal systems and customer funds were not affected; it blocked the unauthorized email source and notified authorities.
- A researcher suggested the incident may have targeted high-net-worth individuals.
Who’s being targeted
- Commonly targeted roles: Compliance, Legal, Customer Support, Fraud Operations, Privacy / Data Protection, Security Operations.
- Affected industries: Digital banking, Retail banking, Cryptocurrency / digital assets.
- Attack channels: email.
- Impersonated: Unnamed official government authority (via legitimate government email domain).
Awareness takeaways
- Treat sensitive data requests as high-risk even when the sender’s email domain looks legitimate; verify through a separate, known-good channel.
- Train compliance/legal/support teams to spot “overbroad” requests (identity documents, facial images, full transaction history) as a major warning sign.
- Don’t rely on email authentication alone as proof of legitimacy; attackers may obtain or create accounts inside trusted domains.
Red flags to watch for
- Request asks for unusually broad/highly sensitive data (ID documents + facial verification + full transaction history).
- Request relies only on email and pressures staff to treat a “legitimate address” as sufficient proof.
- No clear department name, jurisdiction, or case reference that can be independently verified.
Read the video transcript
Revolut shared passport scans and full transaction histories because of one email that looked like it came from a real government address. The message said, “This is an official request from our department,” and asked them to reply with identity documents, facial verification images, bank statements, and full Bitcoin transaction history. Here’s the trap: the email really did come from inside a government domain, so filters trusted it. But there was no clear department name, no case reference, and the scope was way too broad for a normal request. If any email asks for ID documents, facial images, or full transaction history, pause and verify it through a known-good channel, like calling the official number on file, before you send a single file.