Revolut confirms customer data breach via fake government requests sent from legitimate agency email domain
Revolut disclosed sensitive customer data—including passport and driver's license copies, verification selfies, IBANs, and transaction histories—to attackers who impersonated a government agency using a legitimate, validly authenticated government email…
Revolut confirmed that sensitive customer data was exposed after its staff fulfilled fraudulent information requests submitted from a legitimate government agency email domain carrying valid domain authentication, treating them as standard legal compliance. The incident is a form of legal-process fraud in which attackers impersonate law-enforcement or government agencies to trick compliance teams into disclosing user data. Exposed data reportedly includes names, dates of birth, postal and email addresses, phone numbers, occupations, passport and driver's license copies, verification selfies, IBANs, account-opening dates, account statements, transaction and withdrawal histories, and Bitcoin wallet references; earlier reporting said selfies and transaction histories were possibly included, while later reporting listed them among the exposed data. Revolut said a 'very limited group of customers' was affected, blocked the offending email address, and notified the affected agency, law enforcement, and regulators, adding that its systems and customer funds were unaffected. The exact number of victims was not disclosed. Security researcher ZachXBT first publicized the breach via Telegram on September 12, reporting that the scam appeared to target high net worth users of the fintech, which serves over 80 million customers. Experts warn the exposed data enables identity theft and targeted phishing.
- Attackers submitted fraudulent information requests from a legitimate government agency email domain with valid domain authentication; Revolut staff fulfilled them as standard legal compliance
- Exposed data reportedly includes names, dates of birth, addresses, phone numbers, email addresses, occupations, passport and driver's license copies, verification selfies, IBANs, account-opening dates, transaction and withdrawal histories,…
- Revolut says a 'very limited group of customers' was affected; the exact number of victims has not been disclosed
- Revolut blocked the offending email address and notified the affected agency, law enforcement, and regulators
- Revolut states its systems and customer funds were unaffected
- ZachXBT first publicized the breach via Telegram on September 12 and said the scam appeared to target high net worth users
- Revolut serves over 80 million customers
- Experts warn the exposed data enables identity theft and targeted phishing
Coverage timelineoldest first · each row is one article
- · 3d agoRevolut confirms customer data breach through fake government requests
TechCrunch · Security· 72
Revolut disclosed customer identity data, including passports and possibly selfies, to an attacker using a legitimate government email domain.
- · 3d agoRevolut confirms customer data breach, falling for fake government requests
Hacker News · security· 65
Revolut confirmed a breach of sensitive customer data after complying with forged government information requests.
- · 1d agoRevolut Confirms Data Breach Through Fake Government Requests
Infosecurity Magazine· 68
Revolut disclosed customers' IDs, selfies, and financial data to impostors sending fraudulent requests from a legitimate government email domain.