British fintech Revolut has confirmed that sensitive customer information was disclosed to an unauthorised party after fraudsters submitted fake information requests using a legitimate government agency’s email domain.
The company says its own systems were not breached and customer funds were unaffected. Instead, the attackers appear to have exploited trust in official-looking government communications to obtain information directly from the company.
Revolut has not disclosed the exact number of affected customers, saying only that a “very limited” number were impacted.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Passports, selfies and transaction histories may have been exposed
According to The Register, customer notifications shared publicly indicate that exposed information may include identity documents such as passports or driving licences, verification selfies, names, dates of birth, addresses, email addresses and phone numbers.
The notifications also reportedly listed IBANs, account statements, withdrawal records and complete transaction histories, including Bitcoin transactions.
Revolut itself has not published a full list of every data type involved.
Reuters independently confirmed that identity documents, including passports and driving licences, as well as contact and personal information were among the data exposed.
This makes the incident especially serious because identity documents and detailed financial histories can be useful for further fraud even when the attacker does not have direct access to the victim’s account.
Attackers allegedly used a real government email domain
The unusual part of the incident is how the request reached Revolut.
The company said an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information.
Revolut has not identified the government agency involved.
After detecting the problem, the fintech said it blocked the address and alerted the relevant government agency, law-enforcement bodies, data-protection authorities and financial regulators.
That suggests the attackers may have compromised or abused access to an authentic government email environment rather than simply creating a lookalike domain.
The distinction matters.
Companies are trained to be suspicious of emails from fake domains. A request arriving from a genuine government address can be far more convincing.
What is a fake law-enforcement or government data request?
Technology and financial companies routinely receive legitimate requests from police, courts and government agencies seeking customer information for investigations.
These requests can involve account records, subscriber details or transaction information and are normally processed through specialised compliance or legal teams.
A fraudulent request attempts to imitate that process.
If the attacker successfully impersonates a government official, the target company may voluntarily hand over information that would otherwise be heavily protected.
That makes this type of attack a form of social engineering at an institutional level.
Instead of tricking an individual customer into revealing an OTP, the attacker tricks the company holding millions of customers’ records into believing an official request is legitimate.
Revolut says its banking systems were not hacked
Revolut has stressed that the incident did not involve a compromise of its internal systems.
“Revolut systems and customer funds are unaffected,” the company said in its statement.
That means the attackers did not, based on current information, break into Revolut’s core banking infrastructure or directly steal money from customer accounts.
But the distinction does not make the incident harmless.
Copies of passports, selfies and detailed financial information can potentially be used for identity theft, targeted phishing or attempts to open accounts elsewhere.
An attacker who knows a victim’s transaction history can also create far more convincing scams.
A fake bank caller, for example, becomes much harder to dismiss if they already know where the victim recently transferred money.
Self-proclaimed attackers demand 10,000 Bitcoin
The Register reported that people claiming responsibility for the breach have posted samples of allegedly stolen data in Telegram groups.
The posts reportedly include information appearing to belong to high-profile individuals, including executives, athletes and performers.
The group is allegedly demanding 10,000 Bitcoin from Revolut and threatening to publish additional customer information.
At the valuation cited by The Register, the demand was worth more than $782 million.
Revolut has not confirmed that the people making the ransom demand are definitely responsible for the breach and did not comment on the demand itself.
That claim therefore remains unverified.
A verification failure may matter more than a technical exploit
The incident highlights a security problem that firewalls and encryption alone cannot solve.
Financial institutions must respond to legitimate government requests, but they also need a reliable method for confirming that the person making the request genuinely represents the agency named in the email.
Checking only the sender domain may no longer be enough.
Sensitive requests can require secondary verification through known contact points, case numbers, signed legal documents or independent confirmation with the agency.
The breach shows why organisations holding high-value personal data increasingly need to treat official-looking communications as potentially hostile until independently authenticated.
Revolut says it has contacted affected customers directly and is providing support.
What this means for you: If Revolut informs you that your data was affected, be especially cautious of calls or messages referring to your real account details, identity documents or past transactions. Contact Revolut only through its official app or support channels and treat unexpected requests for passwords, OTPs or fund transfers as suspicious.
The420 Insight: The attackers did not need to defeat Revolut’s banking security if they could successfully impersonate the government. The case shows how cybercrime is shifting from breaking systems to exploiting the trust relationships between institutions — and why a genuine email domain can sometimes be more dangerous than an obvious phishing address.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics