Revolut Data Breach Exposes Customer Passports and Transaction Histories
Key Takeaways Fintech giant Revolut experienced a data security incident stemming from a sophisticated social engineering attack. Sensitive Know Your Customer (KYC) documentation, including passport...
Key Takeaways
- Fintech giant Revolut experienced a data security incident stemming from a sophisticated social engineering attack.
- Sensitive Know Your Customer (KYC) documentation, including passport copies, identity verification selfies, and complete transaction histories (including Bitcoin activity), were exposed for a limited number of users.
- The breach was not due to a compromise of Revolut’s core systems but rather an impersonation operation leveraging an unauthorized email from a government agency’s domain.
- The incident raises significant concerns about identity theft, targeted scams, and the broader security implications of mandatory KYC data collection.
Revolut Discloses Data Breach Stemming from Sophisticated Impersonation Attack
Revolut, a prominent financial technology company, has confirmed a data security incident that led to the unauthorized disclosure of sensitive customer information. The breach occurred after the company responded to a fraudulent data request that appeared to originate from an official government entity.
Table Of Content
Details of the Exposure
The incident exposed highly sensitive Know Your Customer (KYC) records and comprehensive financial data belonging to a restricted number of users. This exposed data reportedly included copies of passports or driver’s licenses, identity-verification selfies, bank account statements, and full transaction histories, critically encompassing Bitcoin-related activities.
Revolut clarified that the disclosure did not arise from a compromise of its fundamental systems, mobile application, or customer accounts. Instead, the company stated it was targeted by a sophisticated impersonation scheme involving an unauthorized email account operating within a legitimate government agency’s email domain.
Due to the message carrying valid domain-authentication credentials, Revolut mistakenly believed it was processing an authentic legal or government information request and subsequently fulfilled it.
The extensive information provided in response to the fraudulent request included customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Exposed document and verification data also encompassed identity document copies, such as passports and driving licenses, alongside facial-verification images submitted during the onboarding process. Revolut emphasized that biometric facial telemetry itself was not compromised, though the loss of document scans and verification selfies still poses substantial risks for identity theft and impersonation.
Financial data compromised included account statements detailing IBANs, account status, account-opening dates, wallet reference numbers, withdrawal records, and complete transaction histories. The inclusion of cryptocurrency transaction records, specifically Bitcoin activity, is particularly concerning as it could enable malicious actors to profile victims’ wealth, trading behavior, wallet usage, and vulnerability to targeted scams.
Social Engineering, Not System Compromise
Revolut characterized the event as an advanced social-engineering attack rather than a breach of its internal infrastructure. The company stated it acted swiftly to block the unauthorized email source, inform relevant authorities, and notify affected customers. Revolut also asserted that customer funds remain secure and that its core systems were not compromised.
Despite these assurances, the incident has reignited concerns regarding the security implications of mandatory KYC data collection across various financial sectors, including traditional banks, fintech platforms, and cryptocurrency services. On-chain investigator ZachXBT, along with other prominent figures in the cryptocurrency community, highlighted assertions that the operation specifically targeted high-net-worth individuals. This demographic faces heightened risks from phishing attempts, SIM-swapping, extortion, physical threats, and sophisticated cryptocurrency theft schemes.
For impacted Revolut customers, the combination of identity documents, contact details, account information, and transaction history provides attackers with ample material to craft highly convincing social-engineering lures. Fraudsters could impersonate Revolut support staff, law enforcement, cryptocurrency exchanges, or tax authorities, leveraging personal information to lend credibility to their deceptive messages.
This case also serves as a stark reminder of how trusted email domains can be exploited when an attacker gains unauthorized access to, or misuses, a legitimate organization’s mail infrastructure. Even emails with proper domain authentication can be malicious if the sending account itself has been compromised. The incident underscores the critical necessity for organizations handling sensitive customer data to independently validate high-risk information requests through out-of-band channels, rather than relying solely on domain authentication or the apparent sender identity.
What You Should Do
- Monitor Accounts Closely: Regularly review your Revolut account statements and other financial accounts for any suspicious activity.
- Enable Multi-Factor Authentication (MFA): Ensure MFA is activated on all your financial accounts, email, and other critical online services.
- Be Wary of Phishing Attempts: Exercise extreme caution with unsolicited emails, calls, or messages, especially those requesting personal information or account details. Verify the legitimacy of any requests through official, independently sourced contact channels.
- Consider Identity Theft Protection: Given the exposure of identity documents, consider enrolling in an identity theft protection service.
- Update Passwords: Use strong, unique passwords for all your online accounts and consider using a password manager.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.