Key Takeaways
Revolut has confirmed that it handed sensitive customer information to an unauthorized third party after being deceived by fraudulent requests that appeared to originate from a legitimate government agency.
The UK fintech said the attacker used an email account operating on an authentic government agency domain, allowing the requests to appear legitimate.
Revolut subsequently disclosed customer information before discovering that the requests were fraudulent, according to Reuters.
The company has not identified the government agency involved or disclosed exactly how many customers were affected. It described the incident as a “sophisticated external impersonation scam” affecting a limited number of customers and said its underlying systems were not compromised.
+68
The scope of information potentially disclosed makes the incident particularly sensitive for cryptocurrency users.
Notifications sent to affected customers said the data could include names, dates of birth, occupations, postal and email addresses, and telephone numbers.
Copies of passports or driving licenses and facial verification images submitted during Know Your Customer checks were also potentially included.
Revolut said account statements, IBANs, account-opening dates, withdrawal records, and full transaction histories could have been disclosed, including records of Bitcoin transactions and wallet reference numbers.
Revolut stressed that passwords, passcodes, and customer funds were unaffected. The company also distinguished between verification selfies, which could have been disclosed, and biometric facial telemetry, which it said was not compromised.
Former Mt. Gox CEO Mark Karpelès said he was among those notified by Revolut. Onchain investigator ZachXBT also drew attention to the incident, suggesting that although the breach appeared limited in scale, it may have targeted high-net-worth customers. Revolut has not confirmed that assessment.
Unlike a conventional cyberattack, the incident did not require hackers to penetrate Revolut’s infrastructure.
The fraudulent communication originated from within a legitimate government domain and carried valid domain authentication credentials. Revolut therefore initially believed it was responding to an authentic government request.
That distinction highlights a different security weakness for banks and crypto platforms: attackers may not need to defeat a company’s technical defenses if they can successfully impersonate an organization that is legally entitled to request customer records.
Revolut’s own privacy policy states that it may share personal information with government agencies when legally required, underscoring why verifying such requests is critical to protecting customer data.
Revolut said it blocked the unauthorized email address after identifying the problem and notified the affected government agency, law enforcement, data protection authorities, and financial regulators. Precautionary protections were also applied to affected accounts.
For Bitcoin holders, the combination of identity documents and financial history is potentially more concerning than either dataset alone.
Transaction records tied to a verified identity could provide attackers with information useful for highly targeted phishing or social-engineering attempts, although there is currently no evidence that affected customers’ crypto or fiat funds were stolen.
The unanswered questions are now likely to center on verification. Revolut has not revealed which government agency’s domain was abused, how the unauthorized account was created or compromised, or precisely how many customer records were released.
What is clear is that Revolut’s technology did not have to be hacked for highly sensitive financial information to leave the company. In this case, convincing the institution that the requester was the government was enough.