Revolut confirmed a breach after an attacker impersonated a government agency and sent fraudulent data requests from what appeared to be a legitimate government email domain. Employees processed the requests as normal legal-compliance work, leading to exposure of sensitive customer identity and account information for a limited number of customers.
Key findings
- An unauthorized third party submitted “fraudulent requests for information” using a “legitimate government agency domain email.”
- Revolut called it “a sophisticated external impersonation scam” and said the requests had “valid technical domain authentication.”
- Revolut employees fulfilled the requests as standard legal compliance, resulting in disclosure of sensitive customer data.
- Reportedly exposed data included PII (name, DOB, address, phone, email, occupation) plus identity documents and selfies; a researcher also alleged exposure of financial details (IBANs, transaction/withdrawal history, Bitcoin wallet reference numbers).
- Revolut said systems and customer funds were not affected and it blocked the address, notified customers, and alerted authorities and regulators.
Who’s being targeted
- Commonly targeted roles: Legal, Compliance, Privacy/Data Protection, Customer Support/Operations, Fraud/Investigations, Security Awareness (customer communications).
- Affected industries: Financial services / fintech.
- Attack channels: email.
- Impersonated: Government agency (using a legitimate government agency email domain).
Awareness takeaways
- Treat emailed ‘government/legal’ data requests as high-risk and independently verify the requester through known, official channels before sharing any customer data.
- Train teams that handle sensitive data (legal/compliance/privacy/operations) that a real-looking sender domain is not enough, attackers can impersonate trusted entities convincingly.
- Warn customers to expect follow-on scams after a breach and to avoid sharing passcodes or one-time security codes with anyone contacting them unexpectedly.
Red flags to watch for
- Request comes via email and asks for unusually broad/sensitive records
- Relies on the sender domain appearing legitimate rather than independent verification
- Process pressure: treated as “standard legal compliance” without stronger validation
Read the video transcript
Imagine this lands in your inbox: “Request for information, legal compliance. Please provide the requested customer records.” And it’s from a real government email domain. That’s exactly how Revolut was tricked. An unauthorized third party used a legitimate government agency domain with valid technical authentication, so the emails passed all the usual checks and were treated as standard legal work. Employees fulfilled the requests and sent over names, addresses, dates of birth, phone numbers, emails, ID documents, even transaction history. All because the sender domain looked right and the process felt routine. Your move: if an email claims to be a government or legal data request, stop. Don’t reply. Independently verify it using a phone number or portal you already trust before sending a single record.