Report Ads

Revolut Confirms Sensitive Customer Data Breach After Falling for Fake Government Requests

Cybersecurity
Stay Secure in a World of Growing Cyber Threats. [TechGolly]

Key Points:

  • Revolut confirmed that unauthorized third parties obtained customer data by sending fraudulent requests through a legitimate government agency email domain.
  • The exposed records include passport copies, driver’s licenses, verification selfies, home addresses, and full Bitcoin transaction histories.
  • The fintech company stated that core systems, customer passwords, biometric facial templates, and account funds remain unaffected.
  • The breach targeted a select group of users, highlighting growing vulnerabilities in how financial platforms verify emergency law enforcement requests.

Digital banking and financial technology giant Revolut confirmed that unauthorized third parties obtained sensitive customer identity records and financial histories after submitting fraudulent data requests through an official government agency email domain. The London-headquartered fintech disclosed customer files after an external impersonator submitted what appeared to be an authentic law enforcement inquiry. The security lapse highlights the expanding threat of fraudulent legal requests targeting the vast compliance databases that regulated financial platforms maintain.

The incident unfolded after an unauthorized sender used a valid email account operating directly within a genuine government agency’s domain infrastructure. Because the email headers carried valid authentication credentials that passed standard digital domain verification protocols, Revolut’s compliance team treated the inquiry as a legitimate legal demand. Staff fulfilled the data request and released customer records before independent follow-up communications revealed that the government agency had not authorized the inquiry.

Customer breach notifications confirm that the exposed information includes government-issued identity documents such as passports and driver’s licenses, along with the verification selfies users submit during account onboarding. The disclosed records also contained full legal names, dates of birth, residential addresses, phone numbers, email addresses, International Bank Account Numbers (IBANs), and detailed account statements. Crucially, the breach handed over full cryptocurrency transaction logs, exposing every incoming and outgoing Bitcoin transfer tied to the affected accounts.

Revolut emphasized that the incident did not involve a technical compromise of its central server infrastructure or banking databases. Attackers did not deploy malware, crack account passwords, or access customer funds. The company also clarified that while raw selfie photographs were included in the disclosed files, derived biometric facial telemetry templates remained protected. Upon uncovering the deception, Revolut blocked the sender’s address, launched an internal review of its legal verification workflows, and alerted data protection authorities, financial regulators, and law enforcement agencies.

Independent blockchain investigators noted that the social engineering attack appeared to target high-net-worth individuals and active cryptocurrency investors. By combining verified government identification documents with home addresses and complete Bitcoin transaction records, the attackers acquired comprehensive financial dossiers on specific individuals. Cybersecurity analysts warn that this specific combination of physical location data and cryptocurrency wealth exposes affected users to severe risks of spear-phishing, digital identity theft, and targeted extortion.

The security failure illustrates the unique dangers surrounding emergency data requests and law enforcement subpoenas across the financial technology sector. Under international legal frameworks, financial institutions must respond rapidly to official government demands for user data during urgent criminal investigations. However, cybercrime syndicates increasingly compromise government email inboxes or exploit insecure administrative portals to forge official requests. When an attacker sends a fraudulent subpoena from a real government domain, standard email security filters cannot detect the deception.

The breach exposes a structural tension within modern financial compliance architectures. Under strict Know-Your-Customer (KYC) and Anti-Money Laundering (AML) regulations, digital banks must collect the most intimate personal identity documents their customers possess. While encryption and multi-factor authentication protect these archives from direct server intrusions, the data remains vulnerable at the operational verification layer where compliance personnel evaluate external legal demands. Stolen identity documents present permanent security risks because individuals cannot easily change their facial features or personal identification numbers.

The disclosure arrives at a critical moment as Revolut scales its global operations and prepares for a landmark initial public offering. Operating as one of Europe’s largest digital banks without physical branches, Revolut serves tens of millions of customers worldwide and is targeting a public market valuation of up to $200 billion. High-profile data exposure incidents invite intense regulatory scrutiny from European and British banking watchdogs, which enforce strict data governance and customer protection mandates.

In response to the incident, cybersecurity specialists are urging financial institutions to overhaul how they authenticate external legal requests. Security experts recommend establishing mandatory out-of-band verification procedures—such as phone call confirmations through verified public directories and cryptographically signed digital warrant portals—before compliance officers release customer dossiers. Relying solely on incoming email domain authentication provides insufficient security when hostile actors operate inside compromised government networks.

As law enforcement agencies investigate the origin of the fraudulent government email, the incident serves as an urgent wake-up call for the global fintech industry. Protecting customer privacy requires more than building impenetrable firewalls and securing database encryption. Financial institutions must construct rigid, multi-layered verification checkpoints to ensure that fraudulent government requests cannot weaponize mandatory compliance archives against the very customers they are designed to protect.

Newsroom
Newsroom
Al Mahmud Al Mamun leads the TechGolly Newsroom team. He served as Editor-in-Chief of a world-leading professional research Magazine. Rasel Hossain is supporting as Managing Editor. Our team is intercorporate with technologists, researchers, and technology writers. We have substantial expertise in Information Technology (IT), Artificial Intelligence (AI), and Embedded Technology.