Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › Revolut says customer data exposed through fake government email
Business

Revolut says customer data exposed through fake government email

By Diego Whitfield · · 2 min read

Revolut has confirmed that sensitive personal information belonging to some of its customers was handed over to a fraudster who posed as a legitimate government official, using an email account tied to an official agency domain to trick the fintech company into releasing the data.

What Was Exposed

According to the disclosure, the compromised information included highly sensitive documents such as customer passports, identity verification selfies, and detailed financial transaction histories. This category of data is particularly damaging in the wrong hands, as it can be exploited for identity theft, account takeovers, and further social engineering attacks against affected users.

The breach did not stem from a traditional hack of Revolut's systems. Instead, the attacker leveraged the credibility of a genuine government agency email domain, making the fraudulent request appear authentic enough to bypass standard verification checks.

A single spoofed email carrying official credentials was enough to pry loose passports, selfies and transaction records.

How the Attack Worked

Impersonating a government authority is a well-worn tactic in fraud, but the use of a real agency domain elevates the threat considerably. Companies routinely comply with legitimate requests from law enforcement and regulators, which creates an opening for criminals who can convincingly mimic official channels.

The incident underscores a persistent weakness across the financial and crypto sectors: even robust internal security can be undermined when trusted external requests are weaponized. Fraudsters increasingly rely on deception rather than brute-force technical intrusions to obtain valuable data.

  • Passports and identity documents were among the leaked items
  • Verification selfies used for onboarding were exposed
  • Transaction histories revealing financial activity were compromised

Broader Implications for Fintech Users

For customers of digital banking and crypto-adjacent platforms, the episode is a reminder that personal data held by fintech firms remains a prime target. Victims of such leaks should remain vigilant against phishing attempts and monitor their accounts for unauthorized activity.

The case also raises questions about the safeguards financial companies use when responding to purported official inquiries. Stronger authentication of government requests and independent verification protocols may become necessary as impersonation schemes grow more sophisticated across the industry.

Was this useful?👍 Yes👎 No