Revolut confirms breach after fake government data requests
Revolut has confirmed that an attacker posing as a government agency tricked it into releasing customer identity documents and contact details; it says the number of customers affected was limited and that funds were untouched.
The 60-second version
Revolut confirmed that a fraudster posing as a government agency tricked it into releasing customer identity documents and contact details; the number of affected customers has not been disclosed.
Key points
- The attacker used a legitimate government domain email to file fraudulent "requests for information" — the same channel banks use for real law-enforcement queries.
- Exposed data included birth dates, addresses, phone numbers, and copies of passports and driver's licenses, and may have included verification selfies and statements.
- Revolut blocked the address, alerted the impersonated agency, law enforcement and regulators, and said funds and systems were unaffected.
Verdict. This was a process failure, not a systems hack — and a reminder that even regulated fintechs can be socially engineered. Affected customers should watch for follow-on phishing and identity-theft risks, not just account fraud.
What happenedA forged official request
Revolut confirmed on Saturday that an unauthorized third party tricked it into releasing customer data by sending what looked like a legitimate government agency email. The attacker used a genuine government domain address to submit fraudulent "requests for information" — the same channel authorities use to demand customer records from financial firms. Revolut said it responded before realizing the requests were fake.
What was exposed
According to the notification emailed to affected customers and reviewed by TechCrunch, the exposed data included identity and contact details — birth dates, postal and email addresses, phone numbers — plus copies of identity documents including passports and driver's licenses. Revolut said the data may also have included verification selfies, account statements, and transaction data.
The crypto security researcher known as ZachXBT publicized the notification on Friday night and said the incident appeared to target high-net-worth users. Revolut did not confirm that, and did not say whether the incident was limited to one market.
Why the scam worked
Banks receive a steady stream of legitimate requests for customer data from law enforcement, tax authorities, and regulators. Those requests are routine and carry legal weight, so they are handled by teams not set up to question their authenticity — precisely the gap impersonation scams exploit. This attacker needed no exploit and no breach: the forged request came from what looked like an official government address.
- A routine channel — official data requests are normal for a bank; the fraudster simply forged one.
- A plausible sender — the email used a real government agency's domain.
- No visible red flag — nothing in the request signaled it was fake until the pattern was noticed.
What Revolut did
Revolut said it blocked the email address once the scam was discovered, alerted the government agency whose name was used, and notified law enforcement and financial regulators. It stressed that its systems and customer funds were unaffected and that affected customers were contacted directly.
Bigger picture
The breach lands at a sensitive moment for Revolut. The fintech has more than 80 million customers worldwide, operates as a bank in more than 30 countries, and recently received conditional approval from the U.S. Office of the Comptroller of the Currency for a national bank charter. It is also reportedly weighing a public listing that could value it at up to $200 billion — context that makes a lapse in vetting official requests more than a footnote.
Nobody broke into the vault. A forged key was handed through the front door.
Bottom line
The incident is a reminder that data security includes process security: knowing who is asking is as important as stopping who is attacking. Companies should verify official data requests through independent channels, and customers should assume that exposed identity documents may be used for identity theft — and act accordingly.