Revolut confirmed that fraudsters exploiting a legitimate government domain successfully obtained sensitive customer records from the company. The fintech acknowledged the incident but has refrained from disclosing the scale of exposure or geographic scope.

According to a statement provided to TechCrunch, which first reported the incident on Friday, Revolut identified what it described as "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information". The company maintained that "Revolut systems and customer funds are unaffected".

The compromised data encompasses dates of birth, residential addresses, email accounts, telephone numbers, and identity documents such as passports and driving licences. TechCrunch also reported that verification selfies, account statements and transaction histories may have been shared, providing attackers with nearly all the information required to impersonate customers elsewhere—and unlike passwords, this material cannot be reset.

Why the Impersonation Succeeded

Financial institutions routinely process requests from law enforcement and government bodies, sometimes under time pressure, and employees are instructed to treat such communications as authentic. An attacker sending messages from a genuine government email domain circumvents the scrutiny that would catch a forged official letterhead. This represents a recognized vulnerability in how authorities request customer data from companies, yet the alternative—treating every official request with suspicion—is equally problematic for banks.

Response and Unanswered Questions

Revolut stated it deactivated the fraudulent email address upon discovery, notified affected customers, informed the government agency whose domain was misused, and escalated the matter to law enforcement and financial regulators. However, the company has withheld critical details: the number of victims beyond describing it as "limited", the affected markets, which agency's domain was compromised, how attackers gained access to it, the duration of the scheme before detection, and whether the government agency itself had been breached.

Crypto investigator ZachXBT brought the incident to public attention on Friday, claiming the scam targeted wealthy individuals. While this characterization has not been independently confirmed, it raises questions given Revolut's recent expansion into private banking, which launched with a £500,000 minimum entry requirement as the company pursues a $200bn valuation.

Regulatory and Reputational Stakes

The incident carries particular weight given Revolut's regulatory standing. The company achieved a $115bn valuation this year, operates banking licences in the UK and France, and has targeted an initial public offering within two years. The European Central Bank has previously instructed Revolut to moderate its pace of product expansion.

Under European data protection regulations, companies must notify their supervisory authority within 72 hours of discovering a personal data breach and must inform affected individuals directly when the risk is substantial. Revolut states it has fulfilled both obligations. However, the rules do not mandate public disclosure, which explains why current information comes only from a company statement and a researcher's post.

The Practical Risk Ahead

Customers whose data was exposed should assume the information is now permanently in circulation. The immediate threat is not account draining—Revolut says this has not occurred—but longer-term identity fraud. Possession of identity documents, a verified photograph, and confirmed contact details creates opportunities to open credit accounts elsewhere or to conduct convincing social engineering attacks against individuals whose personal details are already known.

The breach required no technical sophistication: no system penetration, no malware, no stolen credentials, no zero-day exploits. Instead, someone simply sent emails from a trusted address to employees trained to respond to such requests. This limitation means Revolut cannot solve the problem unilaterally, as the trust being exploited belongs to government institutions rather than to the bank itself.

Source: The Next Web