Revolut Data Breach: Attackers Impersonate Government for Customer Data
Key Takeaways Fintech firm Revolut confirmed a data breach stemming from an advanced impersonation scam. Attackers exploited trust in a legitimate government agency’s email domain to obtain...
Key Takeaways
- Fintech firm Revolut confirmed a data breach stemming from an advanced impersonation scam.
- Attackers exploited trust in a legitimate government agency’s email domain to obtain sensitive customer data, including KYC information, financial records, and identity documents.
- The incident did not involve a direct breach of Revolut’s systems or customer funds but exposed critical personal and financial data.
- While Revolut states a “limited” number of customers were affected, unverified claims suggest a larger scale, potentially involving 147 GB of data and multiple Italian law enforcement departments.
- The breach highlights systemic vulnerabilities in how financial institutions verify official data requests, emphasizing the need for robust multi-factor authentication beyond email domain validation.
Revolut Falls Victim to Sophisticated Government Impersonation Scam, Customer Data Exposed
British fintech giant Revolut has confirmed a data breach where an unauthorized third party successfully acquired sensitive customer information. The breach did not originate from a direct attack on Revolut’s internal systems but rather from an elaborate impersonation scheme leveraging the email domain of a legitimate government agency.
Table Of Content
How the Impersonation Scam Unfolded
Unlike traditional cyber intrusions that exploit software vulnerabilities or penetrate network defenses, this incident bypassed Revolut’s core security infrastructure by exploiting a trust relationship. Attackers submitted fraudulent information requests using an email address that appeared to originate from an official government domain, leading Revolut to inadvertently release customer data through its established disclosure protocols.
Revolut’s communication to affected customers clarified that the malicious requests came from an unauthorized email account operating under the official domain of an unnamed government body. The messages carried valid domain-authentication credentials, such as SPF, DKIM, and DMARC, which typically verify an email’s sender. This led Revolut to process the requests under the mistaken belief that they were legitimate governmental inquiries.
The company has characterized the event as a “sophisticated external impersonation scam,” emphasizing that its internal systems and customer funds remained secure. However, this technical distinction does not negate the significant risk posed by the exposure of sensitive data.
While email authentication protocols confirm that a message passed through authorized infrastructure, they do not verify the legitimacy of the individual sending the email or the legality of the request itself. If an attacker had compromised an actual agency account, successful domain authentication would be expected, making the fraudulent requests appear genuine.
Scope of Exposed Customer Data
The data disclosed in the breach encompasses a wide array of Know Your Customer (KYC) information. This includes full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Furthermore, identity verification materials such as passport or driving license copies, along with facial images submitted during the onboarding process, were also compromised. Revolut explicitly stated that biometric facial telemetry was not involved or exposed.
Financial records potentially exposed include account statements with IBANs, account status, opening dates, wallet reference numbers, withdrawal records, and comprehensive transaction histories, including Bitcoin activity. This combination of verified identity, home address, banking behavior, account identifiers, and cryptocurrency holdings presents a particularly potent risk for victims.
Revolut maintains that only a “limited” number of customers were affected and that these individuals have been contacted directly. The company has not publicly disclosed the exact number of impacted individuals, the identity of the government agency whose domain was exploited, whether the incident was geographically restricted, the number of successful fraudulent requests, or the duration of the malicious activity.
Unverified Claims Suggest Broader Impact
Cryptocurrency investigator ZachXBT, who initially brought the customer notification to public attention, suggested that the operation may have specifically targeted high-net-worth individuals. Separately, International Cyber Digest reported claims from a threat actor named “IAmNotAVillain,” who alleged that multiple Italian law enforcement departments had been compromised and that the Revolut operation spanned six months. This actor also claimed possession of 147 GB of data related to Italian entities. It is crucial to note that these allegations remain unverified and should not be treated as confirmed facts regarding the breach.
A screenshot purportedly from the alleged actor, bearing their watermark, appears to show multiple archives labeled “Document Revolut,” email correspondence using an Italian certified-email address, and an extracted folder containing 688 files across 204 subfolders. While this image aligns with the broader claim of repeated abuse of formal law enforcement channels, screenshots alone cannot definitively establish authenticity, provenance, completeness, or the sender’s true identity.
Revolut confirmed that it blocked the malicious email address upon detecting the scam and promptly notified the relevant government agency, law enforcement, data protection authorities, and financial regulators. Affected customers were also directly informed.
Despite assurances that Revolut’s systems were not breached and customer funds are safe, the exposure of durable identity documents and detailed financial records creates significant downstream risks for affected individuals.
What You Should Do
- Exercise Extreme Caution: Treat any unsolicited communication (calls, emails, SMS) quoting accurate account details as untrusted. Never provide personal or financial information in response to such requests.
- Verify via Official Channels: Only verify communications through Revolut’s official app or by contacting their customer support directly using numbers or channels provided on their official website.
- Strengthen Account Security: Enable multi-factor authentication (MFA) on all email and mobile accounts. Use strong, unique passwords and consider a password manager.
- Monitor Financial Activity: Regularly review bank statements, credit card statements, and credit reports for any suspicious transactions or unauthorized activity. Report anything unusual immediately.
- Be Alert for Phishing and Identity Fraud: Be vigilant against targeted phishing attempts, SIM-swapping scams, and any efforts to impersonate financial institutions or government agencies. Criminals may use the exposed data to make these attacks highly convincing.
- Consider Credit Freezes/Fraud Alerts: For those significantly impacted, consider placing fraud alerts or credit freezes with major credit bureaus to prevent new accounts from being opened in your name.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.