Fintech Giant Fooled by Spoofed Government Request
Revolut has disclosed a data breach affecting an undisclosed number of customers after a threat actor successfully impersonated a government agency to obtain sensitive account data. The company says the incident was contained quickly, but the scope of exposed data is severe for those affected.
How the Attacker Got In
The attacker sent an email requesting customer data that appeared to come from a legitimate government agency, using what Revolut described as the agency's official email domain. Because the message carried valid domain authentication credentials, Revolut fulfilled the request "under the reasonable belief that it was an authentic government agency request."
In other words, this wasn't a technical exploit — it was a social engineering and email-spoofing attack that slipped past domain-verification checks that would normally be trusted signals of legitimacy.
What Was Exposed
| Category | Data Exposed |
|---|---|
| Identity | Full name, date of birth, occupation |
| Contact | Postal address, email, phone number |
| Verification | Passport and/or driver's license copies, facial verification selfies |
| Financial | Account statements, IBAN numbers, withdrawal records, full transaction histories (including Bitcoin transactions) |
The combination of government ID scans, biometric selfies, and complete financial histories makes this a high-value dataset for identity theft, account takeover, and targeted fraud.
Scale and Targeting
Revolut declined to disclose exact victim numbers, describing the impact as affecting a "very limited" number of customers. However, crypto fraud investigator ZachXBT suggested the breach "seems to have been targeted at high net worth users" — raising the stakes for those individuals well beyond a typical mass-breach scenario.
Revolut's Response
Revolut stated that core systems and customer funds were unaffected:
"Revolut systems and customer funds are unaffected. Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators."
Not Revolut's First Breach
This marks Revolut's second disclosed breach. In 2022, attackers accessed the personal data of 50,150 customers through a separate incident. The recurrence underscores that fintechs handling large volumes of sensitive identity and financial data remain high-value, repeat targets — and that process-level failures (trusting a spoofed but domain-authenticated request) can be just as damaging as technical vulnerabilities.
Protective Steps for Affected Users
- Assume ID documents are compromised — monitor for identity-theft attempts using your passport or driver's license number.
- Watch for targeted phishing referencing your real transaction history or account details.
- Enable additional account monitoring and transaction alerts within the Revolut app.
- Be skeptical of unsolicited contact claiming to be from Revolut, government agencies, or law enforcement following this breach.