Revolut Discloses Sensitive Customer Data After Falling for Government Domain Spoofing Scam
Revolut, the UK-based digital banking and fintech platform, inadvertently shared highly sensitive customer information with an unauthorized third party after being deceived by fraudulent requests sent via a legitimate government agency’s email domain. The incident, which did not involve a direct breach of Revolut’s systems, occurred when attackers used an unauthorized email account with valid domain authentication credentials to impersonate the agency.
The exposed data included full names, dates of birth, postal and email addresses, phone numbers, and occupations. More critically, the attackers obtained copies of passports, driving licenses, and facial verification images collected during Revolut’s identity checks. Financial records such as account statements, IBANs, transaction histories (including Bitcoin transactions), and withdrawal details were also disclosed. Revolut confirmed that biometric facial telemetry remained secure.
Among those notified was former Mt. Gox CEO Mark Karpelès, who shared excerpts of the email on X. Blockchain investigator ZachXBT reported the breach appeared to affect a limited number of users, potentially targeting high-net-worth individuals, though Revolut has not confirmed this. The company has not disclosed the total number of affected customers, the timeline of the data release, or whether the stolen records were used elsewhere.
Revolut described the attack as a “sophisticated external impersonation” and stated it fulfilled the requests under the belief they were legitimate. After verifying with the government agency, Revolut discovered the fraud, blocked the email address, and alerted authorities, regulators, and impacted customers. The company emphasized that its systems and customer funds remained unaffected.
This incident follows previous security issues at Revolut, including a 2023 flaw in its US payment system that led to $23 million in losses (with $20 million unrecovered) and a 2022 breach linked to the Lapsus$ hacking group. Unlike traditional data breaches, this case highlights the risks of social engineering attacks exploiting trusted communication channels.
Source: https://hackread.com/revolut-gave-customer-data-to-scammers-fake-requests/
Revolut TPRM report: https://www.rankiteo.com/company/revolut
"id": "rev1789223034",
"linkid": "revolut",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Financial Services',
'location': 'United Kingdom',
'name': 'Revolut',
'type': 'Fintech / Digital Bank'}],
'attack_vector': 'Fraudulent email with legitimate government domain '
'authentication',
'customer_advisories': 'Yes',
'data_breach': {'data_encryption': 'No (biometric facial telemetry remained '
'secure)',
'data_exfiltration': 'Yes',
'file_types_exposed': ['Passport copies',
'Driving licenses',
'Facial verification images',
'Account statements',
'Transaction records'],
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Full names',
'Dates of birth',
'Postal and email addresses',
'Phone numbers',
'Occupations',
'Passport copies',
'Driving licenses',
'Facial verification images',
'Account statements',
'IBANs',
'Transaction histories '
'(including Bitcoin '
'transactions)',
'Withdrawal details']},
'description': 'Revolut, the UK-based digital banking and fintech platform, '
'inadvertently shared highly sensitive customer information '
'with an unauthorized third party after being deceived by '
'fraudulent requests sent via a legitimate government agency’s '
'email domain. The incident did not involve a direct breach of '
'Revolut’s systems but occurred due to attackers using an '
'unauthorized email account with valid domain authentication '
'credentials to impersonate the agency.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': 'Highly sensitive customer information',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'initial_access_broker': {'entry_point': 'Fraudulent email with government '
'domain authentication',
'high_value_targets': 'Potentially high-net-worth '
'individuals (unconfirmed)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Highlights the risks of social engineering attacks '
'exploiting trusted communication channels and the need '
'for stricter verification processes for government agency '
'impersonation.',
'post_incident_analysis': {'corrective_actions': ['Blocked the fraudulent '
'email address',
'Alerted authorities and '
'regulators',
'Notified impacted '
'customers'],
'root_causes': 'Lack of verification for '
'government agency impersonation '
'via email'},
'recommendations': ['Implement multi-factor verification for sensitive data '
'requests from government agencies',
'Enhance employee training on social engineering and '
'impersonation scams',
'Strengthen domain authentication and monitoring for '
'fraudulent activity'],
'references': [{'source': 'Revolut Public Disclosure'},
{'source': 'Mark Karpelès (X/Twitter)'},
{'source': 'ZachXBT (Blockchain Investigator)'}],
'regulatory_compliance': {'regulatory_notifications': 'Yes'},
'response': {'communication_strategy': 'Public disclosure and customer '
'notifications',
'containment_measures': 'Blocked the fraudulent email address',
'incident_response_plan_activated': 'Yes',
'law_enforcement_notified': 'Yes',
'remediation_measures': 'Alerted authorities, regulators, and '
'impacted customers'},
'stakeholder_advisories': 'Authorities, regulators, and impacted customers '
'notified',
'title': 'Revolut Discloses Sensitive Customer Data After Falling for '
'Government Domain Spoofing Scam',
'type': 'Social Engineering / Impersonation Scam',
'vulnerability_exploited': 'Lack of verification for government agency '
'impersonation'}