Revolut exposed customer data after fake government requests

Revolut exposed customer data after fake government requests

TechCrunch reported that Revolut disclosed customer data after fraudulent information requests came from an email domain used by a legitimate government agency.

The breach did not come from a direct hack of Revolut systems. The key failure was request verification. An unauthorized party used an official-looking channel to get customer information from the fintech company.

What data was exposed

Revolut told affected customers that the exposed data included personal, identity, and account information. TechCrunch reported these categories:

  • Birth date, postal address, email address, and phone number.
  • Passport and driver's license copies.
  • In some cases, verification selfies, account statements, and transaction histories.

Revolut said a limited number of customers were affected. The company did not share a count, the scope by country, or the agency name. Revolut also said customer funds and internal systems were unaffected.

Here are samples that were shared across the internet:

What data was exposed revolut
What data was exposed revolut

What Revolut did next

Revolut blocked the email address after detecting the issue. The company also alerted the agency, law enforcement, and regulators.

Crypto investigator ZachXBT said the breach appeared to target high-net-worth users. That detail raises fraud risk for affected customers, even without direct account compromise. Identity documents, selfies, statements, and transaction histories give attackers strong material for impersonation and targeted phishing.

What security teams should take from this

Legal request handling is a security surface. Any service holding identity documents, financial records, or payment history should treat official-looking requests as a possible attack path.

Useful controls include request-channel allowlists, out-of-band confirmation with the agency, sender-domain checks, second review for sensitive exports, and audit logs for every disclosure. The Revolut case shows how a trusted email domain still needs independent verification before customer data leaves the company.

Key takeaways

Revolut has more than 80 million customers and operates as a bank in more than 30 countries. The company has expanded in India, Mexico, France, and the UAE, and TechCrunch says US national bank approval is expected in the first half of 2027.

For a fintech company at this scale, a fake legal request process creates risks beyond a single support mistake. Customers trust these companies with identity documents, money movement, and transaction history. Even a narrow breach can have broad consequences when exposed data helps attackers sound credible.


Comments:

Please log in to be able add comments.