Revolut Exposed Customer Data After Falling for Fake Government Requests
The fintech giant handed over passports and crypto records to fraudsters using a legitimate government email domain.
Revolut has admitted to exposing sensitive customer data after being deceived by fraudsters impersonating a government agency. The breach occurred not through a technical system failure, but through a social engineering scheme that exploited the company's trust in official communication channels.
According to reports from BeInCrypto and CyberInsider, attackers used an unauthorized email account hosted on a legitimate government email domain to submit fraudulent data requests. Revolut complied with these requests, resulting in the exposure of highly sensitive information for a limited number of users. The compromised data included passports, Bitcoin records, IBANs, account status, and account opening dates. Additionally, the fraudsters obtained wallet reference numbers, withdrawal records, and complete transaction histories.
The Verification Gap
The incident was first brought to light by blockchain investigator ZachXBT. The breach highlights a critical vulnerability in how fintech companies verify law enforcement or government data requests. In this instance, Revolut relied on the legitimacy of the email domain itself to authenticate the request, failing to account for the possibility that an unauthorized user within a government organization could misuse such an account or that the account had been compromised.
Implications for User Security
This exposure is particularly significant because it bypassed Revolut's technical security perimeter entirely. By leveraging social engineering, the attackers gained access to a comprehensive dataset that allows for highly targeted attacks. The combination of passports and full transaction histories—especially for cryptocurrency users—creates a severe risk of identity theft and sophisticated phishing campaigns. When attackers possess a user's full financial history and government identification, they can craft convincing lures that are far more effective than standard spam.
Industry Outlook
As fintechs continue to scale, the pressure to comply quickly with regulatory and law enforcement requests often clashes with rigorous verification protocols. This event serves as a warning to the broader financial technology sector to move beyond domain-based verification and implement multi-factor authentication or official portal-based requests for sensitive data. For now, the industry is watching to see if other platforms have fallen victim to similar impersonation tactics using official government infrastructure.