Revolut: Revolut Data Breach Via Fake Government Requests – What We Know So Far

Revolut: Revolut Data Breach Via Fake Government Requests – What We Know So Far

Revolut Data Breach Exposes Sensitive Customer Records via Fraudulent Government Requests

Revolut, the British fintech firm, has confirmed a data breach in which an unauthorized third party obtained sensitive customer records by submitting fraudulent information requests through an email address using a legitimate government agency’s domain. Unlike traditional cyberattacks, the breach did not involve compromising Revolut’s app or banking infrastructure. Instead, the attacker exploited trust in an apparently authentic government communication, leading to the release of customer data through an established disclosure process.

The fraudulent request originated from an email account under an unnamed government agency’s official domain, carrying valid domain-authentication credentials (SPF, DKIM, and DMARC). Revolut processed the request under the assumption it was legitimate, later characterizing the incident as a “sophisticated external impersonation scam.” While the company confirmed that its systems and customer funds remained unaffected, the breach exposed a wide range of sensitive data.

Affected records included full names, dates of birth, occupations, postal and email addresses, phone numbers, passport or driver’s license copies, facial images from onboarding, account statements (IBANs, opening dates, wallet references), withdrawal records, and complete transaction histories including Bitcoin activity. Revolut stated that biometric facial telemetry was not compromised. The combination of verified identity documents and financial details poses significant risks for identity fraud, phishing, and targeted extortion.

Revolut described the number of affected customers as “limited” but did not disclose the exact figure, the compromised government agency, the duration of the breach, or whether the incident was confined to a single country. However, crypto investigator ZachXBT suggested the operation may have targeted high-net-worth users. Separately, a threat actor using the alias “IAmNotAVillain” claimed that multiple Italian law-enforcement departments were compromised and that the breach lasted six months, allegedly yielding 147 GB of data. These claims, including a circulated screenshot showing archives labeled “Document Revolut,” remain unverified.

Revolut stated it blocked the fraudulent email address upon detection and notified the relevant government agency, law enforcement, data-protection authorities, and financial regulators. While the company emphasized that its systems were not breached, the exposure of durable identity documents and financial records creates long-term risks for affected customers.

The incident underscores a critical vulnerability in government-data-request workflows: authenticated email alone is insufficient for high-risk disclosures. Organizations handling such requests should implement additional safeguards, including independent verification, case-number validation, dual approval, anomaly detection, and strict data minimization.

The full scope of the breach including the compromised agency, duration, and victim count remains unclear as investigations continue.

Source: https://cybersecuritynews.com/fintech-revolut-data-breach/

Revolut cybersecurity rating report: https://www.rankiteo.com/company/revolut

"id": "REV1789446290",
"linkid": "revolut",
"type": "Breach",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Limited (exact number '
                                              'undisclosed)',
                        'industry': 'Financial Services',
                        'location': 'United Kingdom',
                        'name': 'Revolut',
                        'type': 'Fintech Company'}],
 'attack_vector': 'Fraudulent Government Request (Email Impersonation)',
 'customer_advisories': 'Issued (details undisclosed)',
 'data_breach': {'data_exfiltration': 'Yes (147 GB claimed by threat actor, '
                                      'unverified)',
                 'file_types_exposed': ['PDF (passport/driver’s license '
                                        'copies)',
                                        'Images (facial onboarding photos)',
                                        'Text (transaction records, account '
                                        'statements)'],
                 'personally_identifiable_information': 'Full names, dates of '
                                                        'birth, postal/email '
                                                        'addresses, phone '
                                                        'numbers, '
                                                        'passport/driver’s '
                                                        'license copies, '
                                                        'facial images',
                 'sensitivity_of_data': 'High (government-verified identity '
                                        'documents, financial records)',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Financial Data',
                                              'Identity Documents',
                                              'Transaction Histories']},
 'description': 'Revolut, the British fintech firm, confirmed a data breach in '
                'which an unauthorized third party obtained sensitive customer '
                'records by submitting fraudulent information requests through '
                'an email address using a legitimate government agency’s '
                'domain. The breach did not involve compromising Revolut’s app '
                'or banking infrastructure but exploited trust in an '
                'apparently authentic government communication, leading to the '
                'release of customer data through an established disclosure '
                'process.',
 'impact': {'brand_reputation_impact': 'High (exposure of sensitive financial '
                                       'and identity data)',
            'data_compromised': 'Full names, dates of birth, occupations, '
                                'postal and email addresses, phone numbers, '
                                'passport/driver’s license copies, facial '
                                'images, account statements (IBANs, opening '
                                'dates, wallet references), withdrawal '
                                'records, transaction histories (including '
                                'Bitcoin activity)',
            'identity_theft_risk': 'High (verified identity documents and '
                                   'financial details exposed)',
            'legal_liabilities': 'Potential (regulatory violations, customer '
                                 'lawsuits)',
            'operational_impact': 'Reputational damage; regulatory scrutiny; '
                                  'customer trust erosion',
            'payment_information_risk': 'High (IBANs, transaction histories, '
                                        'and withdrawal records exposed)'},
 'initial_access_broker': {'entry_point': 'Fraudulent government email request',
                           'high_value_targets': 'Potential (high-net-worth '
                                                 'users suggested by ZachXBT)'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Authenticated email alone is insufficient for high-risk '
                    'disclosures; organizations should implement additional '
                    'safeguards (independent verification, case-number '
                    'validation, dual approval, anomaly detection, data '
                    'minimization).',
 'motivation': 'Data exfiltration for identity fraud, phishing, or targeted '
               'extortion',
 'post_incident_analysis': {'corrective_actions': 'Enhanced verification '
                                                  'protocols for government '
                                                  'requests; additional '
                                                  'safeguards (independent '
                                                  'validation, dual approval, '
                                                  'anomaly detection)',
                            'root_causes': 'Insufficient verification of '
                                           'government data requests; '
                                           'over-reliance on email domain '
                                           'authentication'},
 'recommendations': ['Implement multi-factor verification for government data '
                     'requests',
                     'Require dual approval for sensitive disclosures',
                     'Validate case numbers independently',
                     'Apply anomaly detection to request patterns',
                     'Enforce strict data minimization in responses'],
 'references': [{'source': 'Revolut Official Statement'},
                {'source': 'ZachXBT (Crypto Investigator)'},
                {'source': "Threat Actor 'IAmNotAVillain' Claims"}],
 'regulatory_compliance': {'regulations_violated': ['GDPR (potential)',
                                                    'Financial Conduct '
                                                    'Authority (FCA) '
                                                    'regulations (potential)'],
                           'regulatory_notifications': 'Yes (data-protection '
                                                       'authorities, financial '
                                                       'regulators)'},
 'response': {'communication_strategy': 'Public disclosure; customer '
                                        'advisories (scope unclear)',
              'containment_measures': 'Blocked fraudulent email address; '
                                      'notified government agency, law '
                                      'enforcement, data-protection '
                                      'authorities, and financial regulators',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes'},
 'stakeholder_advisories': 'Government agency, law enforcement, '
                           'data-protection authorities, financial regulators '
                           'notified',
 'threat_actor': "Unauthorized third party (alias 'IAmNotAVillain' claimed "
                 'involvement)',
 'title': 'Revolut Data Breach Exposes Sensitive Customer Records via '
          'Fraudulent Government Requests',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Insufficient verification of government data '
                            'requests; reliance on email domain authentication '
                            '(SPF, DKIM, DMARC) alone'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.