Revolut Confirms Data Breach After Fake Government Request Exposes Customer Records

Revolut disclosed sensitive customer records, including identity documents and financial data, after fraudulent requests arrived through a legitimate government agency domain.
Revolut logo centered on a dark blue cybersecurity background with bright blue and purple digital streaks.

Revolut has confirmed a data breach involving highly sensitive customer information after an unauthorized third party used a legitimate government agency email domain to submit fraudulent requests for customer records.

The British fintech company described the incident as a sophisticated external impersonation scam. Unlike a conventional intrusion, Revolut said its own systems were not compromised. Instead, the company disclosed information after receiving requests that appeared to originate from a legitimate government authority.

The information potentially handed over includes identity documents, verification selfies, contact information, bank account details, account statements and transaction histories. For some affected customers, the disclosed records also included Bitcoin transaction information.

Revolut said only a limited number of customers were affected but has not disclosed an exact figure or identified the government agency whose domain was abused.

Fraudulent requests came from legitimate government domain

The unusual access method is central to the incident. According to notifications sent to affected customers, the fraudulent request originated from an unauthorized email account created within an official government authority’s domain infrastructure.

The messages carried legitimate domain authentication credentials, making the requests appear to originate from the government agency they purported to represent.

Revolut fulfilled the requests under the belief that they were authentic. The company later independently contacted the relevant government agency to validate the request and discovered that the account used to obtain the information was unauthorized.

Revolut subsequently blocked the email address across its systems and notified the affected government agency.

The company has not disclosed how the unauthorized account was created or obtained, whether the government agency itself suffered a broader compromise, or how long the account was capable of sending apparently legitimate requests.

Passports, selfies and transaction records potentially exposed

The information disclosed varied between affected customers, but notifications indicate that the exposed records could contain a significant collection of identity and financial information.

Potentially compromised information includes names, dates of birth, postal addresses, email addresses and telephone numbers, along with copies of government-issued identification such as passports and driver’s licenses.

Verification selfies used during identity checks were also potentially disclosed.

Financial information may include IBANs, account statements, withdrawal records and transaction histories. Some customers were informed that their complete Bitcoin transaction histories were among the records potentially provided to the unauthorized requester.

The combination creates a particularly sensitive exposure. Identity documents and verification photographs could support impersonation attempts, while transaction records and account information could provide attackers with detailed knowledge of a victim’s financial activity.

Cryptocurrency transaction histories present an additional concern because they can potentially allow information from an identified customer account to be correlated with activity on public blockchains.

Revolut says accounts and customer funds remain secure

Revolut said the incident did not involve unauthorized access to its systems and that customer funds were not affected.

The disclosure therefore differs from an intrusion in which attackers penetrate a financial institution’s infrastructure and extract records directly. In this case, the attacker allegedly exploited the trust associated with a legitimate government domain to persuade Revolut to provide the information.

Revolut said it has implemented precautionary protection measures for affected customers and contacted those whose information was involved.

The company has also notified law enforcement, relevant data protection authorities and financial regulators as part of its response.

Revolut has not publicly disclosed evidence that the exposed information has been used to access customer accounts or steal funds.

Incident highlights risks around government data requests

The breach demonstrates a different path to sensitive financial information that does not require directly compromising the organization holding the data.

Financial institutions routinely receive legitimate requests for customer records from law enforcement agencies, regulators and other government authorities. An attacker capable of controlling an account within a trusted government domain can therefore exploit an existing channel designed for legitimate information sharing.

Standard email authentication can establish that a message originated from infrastructure authorized to send mail for a particular domain. It does not necessarily establish that the individual controlling a particular mailbox is authorized to make the request contained in the message.

Revolut’s subsequent decision to independently contact the government agency uncovered the fraudulent request, but only after customer information had already been disclosed.

The company has not identified the affected government authority, citing the ongoing investigation. It also remains unclear whether the attacker used the compromised government account to request information from other financial institutions.

Revolut said it is continuing to work with law enforcement and regulators while notifying affected customers directly. The total number of customers whose information was disclosed remains unknown.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site