Revolut Disclosed Customer Data After Fraudulent Government Requests
Key Takeaways
- Fraudulent Requests Led to Data Disclosure: Revolut confirmed that it released sensitive customer information after an unauthorized third party submitted fraudulent requests using the legitimate email domain of a government agency.
- Identity and Financial Records Were Exposed: The disclosed information included contact details and copies of passports and driver’s licenses, while verification selfies, account statements and transaction histories may also have been affected.
- Revolut Has Not Disclosed the Scale: The company said a “limited” number of customers were affected but did not provide a figure, identify the government agency involved or say whether the incident was confined to a particular market.
- Revolut Says Its Systems Were Not Breached: The company said its systems and customer funds were unaffected, distinguishing the incident from a direct intrusion into its banking infrastructure.
Deep Dive
Revolut handed sensitive customer records to an unauthorized third party after receiving fraudulent information requests that came from the legitimate email domain of a government agency, the British fintech confirmed to TechCrunch.
The records were not taken through a reported intrusion into Revolut’s systems. They were disclosed because the requests appeared to be genuine. According to a notification sent to affected customers and reviewed by TechCrunch, the information exposed included dates of birth, postal and email addresses and phone numbers, along with copies of identity documents such as passports and driver’s licenses. Revolut said the disclosed information may also have included verification selfies, account statements and transaction histories.
A Revolut spokesperson described what happened as a “sophisticated external impersonation scam” in which an unauthorized third party used the legitimate email domain of a government agency to submit fraudulent requests for customer information.
The company has not identified the agency involved, nor has it explained how the third party came to control or otherwise use an email address on the agency’s domain. Revolut also declined to say whether the affected customers were confined to a particular country or market. How many people were caught up in the incident is similarly unclear. Revolut told TechCrunch that a “limited” number of customers were affected and said it had contacted them directly, but it did not provide a figure.
After discovering the scam, Revolut said it blocked the email address used to make the requests and alerted the government agency, law enforcement and relevant regulators.
“Revolut systems and customer funds are unaffected,” the company told TechCrunch.
The assurance draws an important boundary around what Revolut says happened. There is no indication from the company that an attacker breached its banking infrastructure or gained direct access to customer accounts. But the records disclosed through the fraudulent requests are themselves unusually sensitive. A password can be changed. A passport number, transaction history or verification image is a different proposition.
Revolut has not publicly detailed the verification procedures applied to the requests, and the information available does not establish which controls failed or whether established procedures were circumvented. What is known is narrower, and perhaps more uncomfortable. The party requesting the records was not entitled to them, yet the request carried enough apparent legitimacy for information to be released.
Crypto security researcher ZachXBT brought wider attention to the incident late Friday after posting about the notification Revolut sent to affected customers. ZachXBT said the breach appeared to have targeted high-net-worth users. Revolut has not confirmed that characterization, and TechCrunch reported that the company did not disclose the number or profile of those affected.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

