Sep 15
/
Latest News
Revolut Discloses Passport and ID Data After Fraudsters Use Real Government Email Domain to Request Customer Records
Revolut has confirmed that sensitive customer information was disclosed after fraudsters used a legitimate government agency email domain to submit fraudulent data requests, allowing the attackers to obtain identity documents and account details under the guise of official inquiries.
In notifications sent to affected customers and reported by TechCrunch, the fintech company said the incident exposed birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports, driver’s licenses, and facial verification images. Crypto fraud investigator ZachXBT said on Telegram that account statements, IBANs, and transaction histories were also accessed, adding that the breach appeared to target high‑net‑worth users.
Revolut described the number of affected customers as “limited,” but acknowledged that the attackers successfully impersonated a government agency by using an email domain with valid technical authentication. Because the requests passed standard domain checks, Revolut processed them as routine legal compliance inquiries.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” a spokesperson said. The company blocked the email address and notified regulators and law enforcement. Revolut emphasized that its internal systems and customer funds were not compromised.
The incident is particularly sensitive for Revolut, which recently secured long‑awaited banking licenses in both the United Kingdom and the European Union after addressing regulatory concerns around compliance and operational controls. The breach highlights how attackers increasingly exploit trusted communication channels rather than attempting to break through hardened technical defenses.
Jake Moore, global cybersecurity advisor at ESET, said the scam demonstrates how difficult such attacks are to detect. “What makes this particularly worrying is that the requests came from a legitimate government email account, making them far harder to spot as a phishing email. The threat actors were able to cleverly disguise themselves as a genuine organisation and simply request the information from Revolut.”
Moore added that cybercriminals often bypass direct attacks on a target’s infrastructure by impersonating trusted sources instead. “Increasingly, cybercriminals don’t need to break through the technical security controls of a final target if they can impersonate a trusted source.”
In notifications sent to affected customers and reported by TechCrunch, the fintech company said the incident exposed birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports, driver’s licenses, and facial verification images. Crypto fraud investigator ZachXBT said on Telegram that account statements, IBANs, and transaction histories were also accessed, adding that the breach appeared to target high‑net‑worth users.
Revolut described the number of affected customers as “limited,” but acknowledged that the attackers successfully impersonated a government agency by using an email domain with valid technical authentication. Because the requests passed standard domain checks, Revolut processed them as routine legal compliance inquiries.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” a spokesperson said. The company blocked the email address and notified regulators and law enforcement. Revolut emphasized that its internal systems and customer funds were not compromised.
The incident is particularly sensitive for Revolut, which recently secured long‑awaited banking licenses in both the United Kingdom and the European Union after addressing regulatory concerns around compliance and operational controls. The breach highlights how attackers increasingly exploit trusted communication channels rather than attempting to break through hardened technical defenses.
Jake Moore, global cybersecurity advisor at ESET, said the scam demonstrates how difficult such attacks are to detect. “What makes this particularly worrying is that the requests came from a legitimate government email account, making them far harder to spot as a phishing email. The threat actors were able to cleverly disguise themselves as a genuine organisation and simply request the information from Revolut.”
Moore added that cybercriminals often bypass direct attacks on a target’s infrastructure by impersonating trusted sources instead. “Increasingly, cybercriminals don’t need to break through the technical security controls of a final target if they can impersonate a trusted source.”
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.