Skip to main content
The Wire
CyberNews by Zentrya One
Data Breaches

Revolut Data Breach Exposes Passports and Full Transaction Histories After Fake Government Request

Fintech giant Revolut has confirmed a data-security incident in which an unauthorized party obtained sensitive customer information after submitting fraudulent requests that appeared to come from a legitimate government agency.

The company said a sophisticated impersonation scam caused a limited number of customers' records to be disclosed. Revolut has not revealed the exact number of affected customers or identified the government agency involved.

Importantly, Revolut said its systems and customer funds were not compromised. The incident involved unauthorized disclosure of customer information rather than a direct breach of its core banking infrastructure.

What Data Was Exposed?

According to customer notifications reported by multiple sources, the information potentially disclosed included:

Data Type Potentially Exposed Information
Identity data Names, dates of birth, occupation
Contact data Home addresses, email addresses, phone numbers
Identity documents Passport and driver's license copies
Verification data Customer verification selfies
Banking information Account statements, IBANs and account details
Transaction data Withdrawal records and complete transaction histories
Crypto activity Bitcoin transaction history

The exposure of identity documents alongside financial and cryptocurrency records creates a particularly sensitive dataset that could be used for targeted phishing, impersonation and other forms of fraud.

How the Attack Worked

The incident appears to have exploited trust in a legitimate government communication channel rather than a technical vulnerability in Revolut's systems.

An unauthorized party used an email account within a legitimate government agency's domain to send fraudulent customer-information requests.

Because the messages appeared to originate from an authentic government domain, the requests passed Revolut's normal verification process and were treated as legitimate.

Revolut later contacted the government agency separately and discovered that the requests were fraudulent.

The company then blocked the unauthorized email address and notified affected customers, regulators, law enforcement and the relevant government agency.

Why the Breach Is Significant

The incident demonstrates that email authentication alone cannot establish that a request is trustworthy.

Even when messages originate from a legitimate domain, an unauthorized mailbox or compromised account inside that organization can potentially be abused to conduct convincing social-engineering attacks.

For financial institutions, requests for highly sensitive customer information should therefore require additional verification, particularly when they involve:

  • Identity documents
  • Full transaction histories
  • Account statements
  • Cryptocurrency activity
  • Customer addresses and contact details

Potential Risks to Customers

Although Revolut says customer funds were unaffected, exposed information could increase the risk of:

  • Targeted phishing and spear-phishing
  • Identity theft
  • Social engineering
  • Account-recovery fraud
  • Financial impersonation
  • Cryptocurrency-related targeting
  • Extortion attempts

The combination of passport information, verification selfies and transaction history can provide attackers with enough context to create highly convincing impersonation scenarios.

What Customers Should Do

Customers who received a breach notification should remain alert for suspicious communications claiming to be from Revolut, banks, government agencies or cryptocurrency services.

They should:

  • Avoid clicking unexpected links or attachments.
  • Never provide passwords, authentication codes or recovery information.
  • Verify unusual requests through official Revolut channels.
  • Monitor accounts and transaction activity for suspicious behavior.
  • Be cautious of calls claiming to be from financial institutions or authorities.
  • Report suspected fraud immediately.

Revolut said it has implemented additional security measures and notified the appropriate authorities. The company continues to investigate the incident.

The breach is a reminder that a valid government email domain does not automatically make a data request legitimate. Organizations handling sensitive financial and identity information need layered verification processes that go beyond domain authentication before releasing customer records.

SEO Meta Description:
Revolut confirms a customer data breach after fraudulent government requests exposed passports, verification selfies, IBANs and full transaction histories, including Bitcoin activity.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.