Revolut Tricked Into Leaking Customer Data via Fake Government Email Request
Revolut has confirmed that fraudsters impersonating a legitimate government agency were able to obtain sensitive customer data by submitting fraudulent "emergency data requests" from what appeared to be a genuine government email domain. The company says a limited number of customers were affected, and those individuals, reportedly high-net-worth people involved in crypto asset businesses, have been notified directly.
Revolut has not named the government domain involved, though leaked material shared on Telegram by a group claiming responsibility suggested it originated from an Italian government address. Italian authorities have not responded to requests for comment, and the Telegram account has since been suspended, meaning not all details of the claim can be verified. The attackers reportedly demanded an extortion payment from Revolut to prevent further release of customer data, something the company declined to confirm.
Once the fraudulent request was detected, Revolut says it blocked the email address involved and alerted the relevant government agency along with law enforcement, data protection, and financial regulators. It remains unclear whether the same compromised or spoofed domain was used to target other financial institutions.