Skip to content
All insights
5 min read

Revolut handed customer data to attackers who emailed from a government domain

The requests passed technical domain authentication and were processed as routine legal compliance. Passports, verification selfies and full transaction histories were disclosed.

Ada

Ada

Writer

Revolut handed customer data to attackers who emailed from a government domain

Revolut has confirmed that it disclosed sensitive customer information to an unauthorised third party after receiving fraudulent requests for information sent from a legitimate government agency email domain.

A Revolut spokesperson told Infosecurity Magazine on 14 September that the requests carried valid technical domain authentication and were fulfilled by Revolut employees as standard legal compliance. The company described the incident as a sophisticated external impersonation scam.

Revolut said its systems and customer funds were unaffected, and that only a very limited group of customers was involved. It declined to give a number, or to say whether the incident affected a particular market or department.

What was disclosed

Revolut did not publish a list of affected data types. Customer notifications shared by blockchain investigator ZachXBT, who publicised the incident on 12 September, indicate the disclosure covered know-your-customer records.

According to those notifications, whichever identity document a customer supplied at registration, passport or driver's licence, was included, along with the verification selfie submitted through the app. The notifications also list account statements, IBANs, withdrawal records and full transaction histories including Bitcoin transactions, as well as full names, dates of birth, home and email addresses, phone numbers and occupations.

Muhammad Yahya Patel, a virtual CISO and adviser at Huntress, told Infosecurity Magazine that the combination amounted to a complete identity theft kit rather than a conventional data leak, and questioned why a regulated financial institution handling data of that sensitivity did not have verification controls capable of catching the requests.

Extortion attempt

People claiming responsibility have posted in multiple Telegram groups. The Register reported seeing posts containing data snippets that appeared to belong to high-profile individuals including chief executives, sports professionals and performing artists.

The posters threatened to release further data daily until Revolut paid, and demanded 10,000 Bitcoin, which The Register calculated at more than 782 million US dollars. Revolut did not comment on the alleged ransom demand when asked.

How the requests reached Revolut

Revolut has not identified the government agency involved, but said it notified the relevant officials of its findings. Its security team blocked the email address on detection and alerted enforcement agencies, data protection regulators and financial regulators.

Capital Brief reported on 16 September that Revolut has confirmed it received an email from an unauthorised third party that had either compromised a government agency's email system or replicated its SPF, DKIM and DMARC domain authentication. Capital Brief also reported it is understood an Italian government agency was accessed or impersonated, that a forged European Investigation Order was used to compel disclosure, and that the customers targeted held large cryptocurrency balances. Revolut has not publicly confirmed those details.

Guidance to customers

Jamie Akhtar, chief executive and co-founder of CyberSmart, told Infosecurity Magazine that the exposed information could be used for identity fraud and closely targeted phishing even though funds were not taken. He advised affected customers to treat unexpected calls, emails or messages claiming to come from Revolut, government bodies or other trusted organisations with caution, never to disclose passwords, passcodes or one-time codes, and to contact Revolut only through its official app or verified website.

He recommended that users of digital financial services generally enable multi-factor authentication, use unique passwords, monitor accounts and credit reports for unusual activity, and report suspected identity misuse promptly.

Australian customers

Revolut has assured regulators that Australian customers were not affected, according to Capital Brief. Patrick Collins, founder of Dam Secure, told the publication that an attack of this kind could happen in Australia, citing the exposure of institutions to impersonation fraud.

Company context

Revolut serves more than 80 million personal customers and more than 800,000 businesses globally. It received approval to launch its UK bank in March. Co-founder and chief executive Nik Storonsky has indicated the company may pursue a public listing, though not before 2028, at a target valuation of around 200 billion US dollars.

The incident is the second social engineering breach the company has disclosed. In 2022, attackers used social engineering to reach data belonging to approximately 50,150 customers.

Book your free security consultation

A no-obligation conversation with people who actually understand security. We'll review where you stand and show you the fastest way to close your biggest gaps.