Revolut discloses customer data breach tied to spoofed government request
Security & Exploits ·
Revolut released sensitive customer records, including identity documents and Bitcoin transaction histories, after staff were misled by a fraudulent email sent from what appeared to be a legitimate government domain.
According to a post detailing the incident, employees at the fintech firm were targeted through social engineering that spoofed an official government address, prompting them to disclose a wide range of customer information. The data handed over reportedly included copies of identification documents, verification selfies used during onboarding, home addresses, IBANs, account statements, and complete transaction histories, with Bitcoin activity specifically named among the exposed records.
The breach highlights how attackers can bypass technical security controls by exploiting internal verification processes tied to seemingly official communications. Rather than a direct system intrusion, the incident appears to stem from a failure to authenticate the source of a data request before releasing customer files, raising questions about how such requests are verified internally before sensitive material is shared externally.
Multiple accounts of the incident circulating separately describe similar details, with some describing the exposed users as high-net-worth customers whose passports, statements, and personal details were compromised. Reports converge on the presence of passport-level identification, financial statements, and Bitcoin-related transaction records among the leaked data, suggesting broad agreement on the scope of what was disclosed even as full details remain limited to these overlapping accounts.
It remains unclear how many customers were affected, when the fraudulent request was received and acted upon, or whether Revolut has issued a formal statement addressing the scope of the exposure. Also unknown is whether any regulatory bodies have been notified or whether the spoofed government domain has been identified and taken down. Until Revolut or an official source provides confirmation, the extent of the breach and any remediation steps remain unverified beyond the accounts circulating about the incident.