Revolut Discloses Customer Data Leak After Scammer Hijacks Government Email Domain
Revolut Discloses Customer Data Leak After Scammer Hijacks Government Email Domain #
Revolut has confirmed that an attacker posing as a government agency used a legitimate official email domain with valid authentication credentials to extract sensitive customer data from the company’s compliance team.
The attacker contacted Revolut’s compliance staff through an email address registered under a real government agency’s domain. Because the messages appeared to come from an authorized source, Revolut fulfilled the data requests.
The disclosed records include full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers, according to notification emails sent to affected customers and reviewed by multiple outlets. Also exposed were copies of government-issued identity documents such as passports and driver’s licences, and facial-verification images submitted during onboarding. Financial records in the disclosure cover account statements, IBAN numbers, account-opening dates, withdrawal histories and full transaction logs, including Bitcoin transaction data.
In a statement to BleepingComputer, Revolut said: “Revolut systems and customer funds are unaffected. Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”
The company did not specify how many customers were affected, identify the government body whose domain was used, or say whether the incident was limited to a particular country or region. Revolut serves more than 80 million customers globally across over 160 countries and regions.
Independent crypto-security researcher ZachXBT, who flagged the breach on Telegram, said the number of victims appeared relatively small but that the attack seemed targeted at high-net-worth individuals.
Security professionals have warned that the combination of identity documents, biometric images and detailed financial records could enable follow-on fraud, including impersonation of Revolut support staff, tax authorities or law enforcement.
This is Revolut’s second publicly disclosed breach in four years. In September 2022, attackers obtained the personal, contact and partial financial data of approximately 50,150 customers. In the latest case, Revolut’s internal systems were not accessed; instead, the company’s compliance processes were manipulated through social engineering.