ZeroHour
Story · 3 sources · 3 articlesfirst updated ()1

Revolut confirms customer data breach via fake government requests sent from legitimate agency email domain

highData breachexploited in the wildimportance 72
What's new: New reporting from Infosecurity Magazine (September 14) adds that the fraudulent emails carried valid domain authentication, expands the list of exposed data to include names, occupations, IBANs, account-opening dates, withdrawal histories, and Bitcoin wallet references, quotes Revolut's 'very limited group of customers' phrasing, confirms ZachXBT first disclosed the breach via Telegram on…
Merged summary · glm-5.3 · rewritten as coverage arrives

Revolut disclosed sensitive customer data—including passport and driver's license copies, verification selfies, IBANs, and transaction histories—to attackers who impersonated a government agency using a legitimate, validly authenticated government email…

Revolut confirmed that sensitive customer data was exposed after its staff fulfilled fraudulent information requests submitted from a legitimate government agency email domain carrying valid domain authentication, treating them as standard legal compliance. The incident is a form of legal-process fraud in which attackers impersonate law-enforcement or government agencies to trick compliance teams into disclosing user data. Exposed data reportedly includes names, dates of birth, postal and email addresses, phone numbers, occupations, passport and driver's license copies, verification selfies, IBANs, account-opening dates, account statements, transaction and withdrawal histories, and Bitcoin wallet references; earlier reporting said selfies and transaction histories were possibly included, while later reporting listed them among the exposed data. Revolut said a 'very limited group of customers' was affected, blocked the offending email address, and notified the affected agency, law enforcement, and regulators, adding that its systems and customer funds were unaffected. The exact number of victims was not disclosed. Security researcher ZachXBT first publicized the breach via Telegram on September 12, reporting that the scam appeared to target high net worth users of the fintech, which serves over 80 million customers. Experts warn the exposed data enables identity theft and targeted phishing.

  • Attackers submitted fraudulent information requests from a legitimate government agency email domain with valid domain authentication; Revolut staff fulfilled them as standard legal compliance
  • Exposed data reportedly includes names, dates of birth, addresses, phone numbers, email addresses, occupations, passport and driver's license copies, verification selfies, IBANs, account-opening dates, transaction and withdrawal histories,…
  • Revolut says a 'very limited group of customers' was affected; the exact number of victims has not been disclosed
  • Revolut blocked the offending email address and notified the affected agency, law enforcement, and regulators
  • Revolut states its systems and customer funds were unaffected
  • ZachXBT first publicized the breach via Telegram on September 12 and said the scam appeared to target high net worth users
  • Revolut serves over 80 million customers
  • Experts warn the exposed data enables identity theft and targeted phishing

Coverage timeline

  1. · 3d ago
    TechCrunch · Security· 72
    Revolut confirms customer data breach through fake government requests

    Revolut disclosed customer identity data, including passports and possibly selfies, to an attacker using a legitimate government email domain.

  2. · 3d ago
    Hacker News · security· 65
    Revolut confirms customer data breach, falling for fake government requests

    Revolut confirmed a breach of sensitive customer data after complying with forged government information requests.

  3. · 1d ago
    Infosecurity Magazine· 68
    Revolut Confirms Data Breach Through Fake Government Requests

    Revolut disclosed customers' IDs, selfies, and financial data to impostors sending fraudulent requests from a legitimate government email domain.