Revolut confirmed a customer data breach after attackers used a compromised government agency domain to submit fake “official” requests for customer information. Revolut provided sensitive details (including IDs like passports and driver’s licenses) based on those email requests, raising questions about verification controls for law-enforcement or government inquiries.
Key findings
- Attackers used a compromised/spoofed government domain to make requests that appeared legitimate.
- Revolut provided customer data in response, including highly sensitive identity documents.
- The article notes uncertainty about how many customers were affected and why email-only requests were sufficient without stronger validation.
Who’s being targeted
- Commonly targeted roles: Customer Support, Compliance, Legal, Fraud/Investigations, Data Privacy, Security Awareness.
- Affected industries: Financial services / Fintech, Banking, Cryptocurrency services.
- Attack channels: email.
- Impersonated: Government agency (using a compromised government domain).
Awareness takeaways
- Treat ‘government’ or ‘law enforcement’ email requests as high-risk and require a strict verification process (approved intake channel, legal review, and callback to a known published number).
- Never release identity documents or transaction history based on email alone; require documented authority and verified identity of the requester.
- Assume trusted domains can be compromised; ‘looks official’ is not proof. Validate the request, not just the sender address/domain.
Red flags to watch for
- Email request for sensitive customer data with no secondary verification (ticketing portal, signed request, callback, or warrant validation).
- Urgent/authoritative tone implying legal pressure to bypass normal checks.
- Request comes from a domain that may look legitimate but could be compromised or misused.
Read the video transcript
Revolut actually handed over passports and IDs because a fake ‘government’ email asked for them. Attackers used a compromised government domain and wrote, 'Hello Revolut Compliance Team, we are requesting customer details in relation to an official government inquiry. Please provide the customer’s address, date of birth, and identity documentation.' And Revolut sent it. Here’s the trap: the domain looked official, but it was compromised. There was no secure portal, no signed warrant, no callback to a published number, just an email, and they still released addresses, birthdates, and ID scans. If an email asks for customer data in the name of ‘government’ or ‘law enforcement,’ stop. Don’t reply. Route it through our official legal intake channel and let them verify it.