Revolut hands over customer data after fake government requests
UK fintech Revolut exposed sensitive customer data after attackers used a legitimate government domain email to request information, per the company. The breach did not compromise systems or funds, but exposed passports, selfies, and transaction histories. Revolut says only a limited number of customers were affected, but attackers are demanding 10,000 Bitcoin (€720M) and have begun releasing data, per The Register.
Bottom line — Attackers used a real government email domain to obtain identity documents and transaction histories from Revolut.
Go deeper (8)
- The request originated from an unauthorised account inside a genuine government agency's domain, making it appear legitimate, according to Revolut.
- Exposed data includes KYC documents (passports, driving licences), verification selfies, full names, addresses, IBANs, and Bitcoin transaction histories, per the customer notification reviewed by TechCrunch and shared by blockchain investigator ZachXBT.
- Crypto investigator ZachXBT said the incident appeared targeted at high-net-worth users, with posts on Telegram threatening to release data unless the ransom is paid.
- Revolut said it blocked the email address after detection and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators.
- The attackers demand 10,000 Bitcoin (€720M), according to posts seen by The Register, but Revolut did not comment on the ransom demand.
- Jake Moore, global cybersecurity advisor at ESET, said a genuine email address does not always mean a genuine request, per IT Pro.
- The incident exploits a known vulnerability: the FBI has warned of criminals using compromised government email addresses to send fraudulent emergency data requests, per Zyphe’s analysis.
- For financial firms, the case underscores that email domain authentication alone is insufficient for verifying government requests, per Cyber Security News.