FinCrunch
← All coverage

Revolut confirms customer data exposed after scammers impersonated a government agency

A fraudulent information request sent from a spoofed but authenticated government domain tricked Revolut’s compliance team into releasing KYC documents and transaction histories.

Samuel OkonkwoRegulation Desk
High-contrast black and white close-up photograph of a padlock with a hairline crack across it, resting on a dark reflective surface under dramatic side lighting

Revolut confirmed that a limited number of customers had sensitive identity and transaction data exposed after an unauthorized third party impersonated a government agency to extract the information, the company said. Revolut said the incident did not compromise customer funds, passwords, or its core banking systems.

According to the company, the attacker sent fraudulent information requests that carried valid domain authentication credentials for a legitimate government agency's email domain, making the requests appear genuine to the compliance staff who received them. Believing the requests were authentic regulatory or law-enforcement inquiries, Revolut's compliance team fulfilled them, releasing the data the fraudulent requests asked for.

The exposed information includes passports, driver's licenses, identity-verification selfies, full contact details, and transaction histories, including records tied to Bitcoin activity, Revolut said. That category of data — the documents and biometric checks banks and fintechs collect to satisfy Know Your Customer, or KYC, rules — is precisely what the compliance process is designed to protect, which is what makes an attack that exploits the compliance workflow itself notable: the failure point was not a hacked database but a request-verification process that treated a spoofed-but-authenticated domain as sufficient proof of legitimacy.

Revolut said it has notified affected customers and relevant regulators and is reviewing its procedures for verifying the authenticity of information requests from outside parties. The company did not disclose the exact number of customers affected.

The incident is a reminder that data-security failures at financial institutions increasingly run through social-engineering and impersonation schemes rather than direct system intrusions — a pattern that has shown up across the industry as attackers target the humans and processes around a system rather than the system's technical defenses.