Fake Government Requests Trick Revolut Into Leaking Customer Data
Revolut has confirmed that a limited number of customers had personal and financial data exposed after fraudsters used an email address on a legitimate government domain to submit fake data requests. The requests passed Revolut's checks before being identified as fraudulent, and by that point information had already been disclosed.
The exposed data may include birth dates, addresses, phone numbers, copies of passports and driving licenses, verification selfies, account statements, and transaction histories, including Bitcoin activity. A crypto investigator who reviewed the notification claimed additional details such as IBANs, withdrawal records, and occupations may also have been affected, and suggested the incident targeted high-net-worth users specifically.
Revolut says its core systems and customer funds were not compromised, and it has blocked the fraudulent sender, alerted the impersonated government agency, and notified law enforcement, data protection authorities, and financial regulators. The incident highlights how attackers can exploit trust in official-looking email domains to bypass standard verification processes at financial institutions.