Revolut says customer data exposed through fake government email

Revolut said a fraudster obtained sensitive customer information after submitting a request that appeared to come from a government agency email domain. The exposed data included passport scans, verification selfies and full transaction histories; Revolut has blocked the address, notified affected customers and informed authorities.

By AI NewsroomPublished about 4 hours agoUpdated about 4 hours ago0 views

Why It Matters

The incident demonstrates how attackers can exploit trusted government domains to bypass authentication and access personal financial and identity data, intensifying concerns about the security costs of mandatory KYC practices and centralized data holdings.

Key Facts

  • Company: Revolut
  • Types of data exposed: Copies of passports, verification selfies, full transaction histories
  • Attack method: Fraudulent information request sent from a legitimate government agency email domain that passed Revolut's authentication checks
  • Discovery and response: Revolut identified the impersonation, blocked the address, and alerted the relevant government agency
  • Notifications: Impacted customers were notified on Friday; Revolut contacted a limited number of affected individuals directly to offer support (spokesperson quoted to Cointelegraph on Saturday)

Revolut has disclosed that a recent impersonation scam led to disclosure of sensitive customer records after the company received a fraudulent information request that appeared to originate from a government agency email domain. The incident allowed an unauthorised party to obtain identity documents and detailed account activity for some customers.

According to a post by International Cyber Digest on X, the message used a legitimate government-domain email address and passed Revolut's authentication checks initially. Revolut later determined the requests were not authentic, blocked the email address, and alerted the government agency whose domain was used.

A company spokesperson told Cointelegraph that the incident involved a “sophisticated external impersonation” and that the firm has informed enforcement bodies and financial regulators. Revolut said its systems and customer funds were not affected and that it has directly contacted the limited number of impacted customers to notify them and provide support.

The episode drew attention in crypto and social-media circles. Investigative contributor ZachXBT suggested the breach appeared limited in scope and might have targeted high-net-worth users, while some users on X criticized the broader system of mandatory KYC after reports that personal data had been exposed. Cointelegraph reported the developments and noted the company response as part of ongoing coverage.

Keep Reading