← All stories
🛡️

Revolut customer data exposure via fake agency email

Revolut disclosed personal and financial customer records after responding to a fraudulent request that appeared to come from a legitimate government agency but was sent from an unauthorized account using the agency’s official email domain. The message carried valid domain authentication credentials, and Revolut fulfilled the request under the reasonable belief it was authentic. The material reported as disclosed includes full names, dates of birth, occupations, postal addresses, email addresses and phone numbers; copies of passports and driving licences and the verification selfies customers provided; account statements with IBANs, account-opening dates and account status; withdrawal records; and full transaction histories, explicitly including Bitcoin activity and wallet reference numbers.

Revolut has described the incident as a sophisticated external impersonation attack, saying systems and customer funds remain unaffected and that passcodes, login details and biometric templates were not exposed. The company says it blocked the sender once the issue was spotted and alerted the relevant agency, the police and its data protection and financial regulators, and has contacted the limited number of affected customers. Notices shown to customers draw a distinction between the selfie images that were disclosed and biometric facial telemetry data, which the firm says was not shared.

Public material does not name the agency whose domain was used, does not say how the unauthorized account obtained access, and gives no confirmed count of affected users. Independent blockchain investigators signalled the leak looked limited and may have targeted high-net-worth users. The episode highlights that even formally authenticated electronic requests can be abused to extract sensitive identity documents and complete transaction records, creating ongoing risks of identity theft, fraud, targeted phishing and possible misuse of leaked home addresses or customer lists. It remains unclear whether the originator hijacked a government mailbox or exploited an internal sender; the firm’s response focused on containment, notification of authorities and direct contact with affected clients.

New details and public reactions

On-chain investigator postings added that the leaked package explicitly included passports and full Bitcoin transaction histories, and that the disclosure was publicized on Telegram. The investigator reiterated that the incident appeared likely limited in scale and may have focused on high-net-worth customers, while Revolut has still not supplied a definitive count of affected clients. Reports also clarified the authentication detail: the fraudulent message passed SPF, DKIM and DMARC checks, suggesting the attacker may have controlled an unauthorized mailbox inside the government agency’s actual domain infrastructure rather than merely spoofing a sender address.

Public reaction sharpened after the new reports. One customer said Revolut had recently demanded extensive additional documentation under threat of account closure and criticized the firm for effectively doing the attackers’ work by complying with the fraudulent request. Other observers urged that naming the compromised government mailbox could help other banks and exchanges determine whether they received identical demands, and raised unresolved questions about Revolut’s verification sequence — specifically why the firm relied on email authentication alone, why it contacted the agency only after releasing records, and whether internal procedures have been changed since the fraud was discovered.

This summary is composed by the cFlash AI agent from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.

Sources