Revolut, Europe’s largest fintech company has disclosed a significant data breach after fraudsters posing as government officials convinced the financial technology company to hand over highly sensitive customer information, including identity documents, account details and transaction histories.
The incident did not involve attackers breaking into Revolut’s core banking infrastructure. Instead, the criminals reportedly exploited the trust attached to an authentic government email domain, using it to submit fraudulent requests for customer information that were initially treated as legitimate.
Revolut described the incident as a “sophisticated external impersonation scam” in which an unauthorised party used an email address associated with a genuine government agency domain. The company said it blocked the address after discovering the deception and notified the affected government agency, law-enforcement bodies, data-protection authorities and financial regulators. “Revolut systems and customer funds are unaffected,” the company said in a statement reported
Although Revolut has publicly characterised the number of affected customers as “very limited,” the company contacted around 700 people following an initial investigation.
The incident is particularly serious because the compromised material reportedly extends beyond basic contact information. Depending on the individual customer, the disclosed records may have included names, dates of birth, postal addresses, email addresses, telephone numbers, account statements, International Bank Account Numbers, withdrawal records, verification photographs, passports, driving licences and detailed transaction histories.
Some customers were warned that records of their Bitcoin activity may also have been disclosed.
Criminals reportedly demand ransom over stolen records
The criminals claiming responsibility have reportedly threatened to release the information publicly unless Revolut pays a ransom, according to the Financial Times.
This gives the incident an extortion dimension even though ransomware was not deployed against Revolut’s infrastructure. Rather than encrypting corporate systems and demanding payment for a decryption key, the attackers appear to be attempting to monetise data that the company itself supplied in response to fraudulent official-looking requests.
The Information Commissioner’s Office has reportedly opened an investigation after Revolut notified the UK privacy regulator. The investigation is expected to examine the circumstances under which the information was released, the safeguards used to validate the requests and whether Revolut took appropriate steps to protect the affected customers.
The company has not publicly identified the government agency whose email domain was used. It has also not said whether the underlying account was compromised by an outside attacker, misused by someone with authorised access or exploited through another mechanism.
That distinction remains important. Possession of an email address on an authentic government domain provides a convincing layer of legitimacy, but it should not, by itself, establish that a request is lawful, accurate or authorised.
Revolut has also not disclosed when the fraudulent requests began, how many requests were processed, whether more than one employee or internal team handled them, or what supporting documentation accompanied them.
A data breach without a conventional system intrusion
The incident illustrates how an organisation can suffer a serious breach without a vulnerability being exploited in its software or an attacker entering its corporate network.
In this case, the target appears to have been the process used to receive, assess and approve official information requests. The criminals exploited institutional trust and procedural weaknesses rather than compromising Revolut’s banking application.
Financial institutions routinely receive requests for customer information from police, courts, regulators, tax authorities and other government bodies. Depending on the jurisdiction and circumstances, those requests may be supported by subpoenas, court orders, warrants, statutory notices or emergency authorities.
Companies are therefore required to maintain mechanisms through which properly authorised officials can request records. Those mechanisms can become attractive targets because they may provide access to information that criminals would otherwise need to steal through a complex technical intrusion.
A request submitted from an authentic government domain can appear especially credible. However, domain ownership only establishes where a message originated; it does not prove that the person sending it is authorised to make the request, that the legal instrument is genuine or that the requested data is proportionate to the stated investigation.
The Revolut case therefore raises questions about whether the company independently confirmed the requester’s identity, checked the legal basis of the request and verified the matter through a separate contact channel before releasing the records.
These questions are especially important when a request seeks identity documents, biometric-style verification images or complete financial histories rather than a narrowly defined set of account records.
Fake official data requests are an established criminal technique
The method used against Revolut is not entirely new. Cybercriminals have spent several years exploiting emergency and law-enforcement data-request procedures to obtain information from technology platforms, financial institutions and service providers.
In a November 2024 warning, the FBI said it had observed an increase in criminal discussions about fraudulent emergency data requests. Attackers were using compromised government and police email accounts, stolen legal documents and social-engineering techniques to make their requests appear legitimate.
The FBI found criminals discussing the purchase and sale of access to government email accounts, including domains belonging to agencies in the United States and other countries. Some also advertised templates, official signatures and guidance for preparing convincing requests.
Emergency data requests are particularly attractive because they may be processed faster than ordinary legal demands. They are intended for circumstances involving an imminent threat to life or serious physical harm, where waiting for a conventional warrant or subpoena could create unacceptable risk.
Criminals attempt to manufacture that urgency. A convincing message may allege a kidnapping, suicide threat, missing child, terrorist plot or another immediate danger, pressuring the recipient to disclose records before all the normal verification steps have been completed.
In 2022, similar schemes reportedly resulted in companies including Apple and Meta disclosing user information to criminals who had submitted forged emergency requests. Those cases demonstrated that even companies with mature security programmes could be manipulated when attackers gained access to trusted government communications infrastructure.
The FBI’s later warning showed that the technique had evolved into a wider criminal market involving compromised official inboxes, stolen documents and paid instruction on how to impersonate law-enforcement personnel.
The Revolut incident suggests the threat remains effective, particularly when an attacker can combine technical access to a trusted domain with detailed knowledge of how official disclosure procedures operate.
Why the exposed information presents a lasting risk
Revolut has stressed that customer funds and its systems were not affected. That is an important distinction, but it does not eliminate the risk facing people whose data was disclosed.
Passwords can be changed and payment cards can be cancelled. Passports, driving licences, dates of birth, home addresses, verification photographs and historical financial records are much more difficult to replace or invalidate.
The combination of identity documents and account information could allow criminals to construct highly convincing impersonation attempts. An attacker could contact a victim while claiming to be from Revolut, another bank, a cryptocurrency exchange, the police or a government agency and then use accurate personal and transactional information to establish credibility.
For example, knowledge of an account balance, recent withdrawal, Bitcoin transaction or bank transfer could make a fraudulent security alert appear genuine. The criminals could refer to information that would ordinarily be known only to the customer and the financial institution, increasing the probability that the victim follows instructions, reveals an authentication code or transfers money to a supposedly secure account.
Copies of identity documents and verification selfies could also be used in attempts to open accounts, bypass identity checks or support fraudulent applications. Many institutions have strengthened their onboarding controls with facial matching and liveness testing, but high-quality identity records remain valuable to criminal groups, particularly when combined with additional personal information.
The reported exposure of home addresses creates a further concern if the victims were deliberately selected because of their wealth or cryptocurrency holdings. Blockchain investigator ZachXBT suggested that the incident appeared to have targeted high-net-worth customers, although Revolut has not publicly confirmed that assessment.
If that theory is correct, the attackers may have been seeking more than information for conventional identity fraud. Detailed knowledge of cryptocurrency activity, identity and physical location can be used for tailored phishing, account takeover, extortion and, in extreme cases, threats of physical harm.
Cryptocurrency exchange Mt. Gox former chief executive Mark Karpelès said he was among the people notified. A copy of the notice he shared publicly indicated that the information potentially supplied included account statements, IBANs, withdrawal records and complete transaction histories, including Bitcoin activity.
The reported inclusion of cryptocurrency information could help attackers identify account holders with significant holdings, analyse how they move assets and design fraud attempts around exchanges, wallets or previous transactions.
Regulatory investigation will focus on security and accountability
Under the UK General Data Protection Regulation, organisations must implement appropriate technical and organisational measures to protect personal information against unauthorised disclosure.
A breach is not limited to data stolen through malware or a network intrusion. Providing personal information to an unauthorised recipient also constitutes a personal-data breach, even if an employee deliberately sent the information after mistakenly believing the recipient was entitled to receive it.
Where a breach is likely to create a risk to people’s rights and freedoms, organisations must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If the risk to affected individuals is considered high, those individuals must also be notified without undue delay. The ICO explains the reporting requirement in itsofficial breach-response guidance.
Revolut said it contacted the affected customers directly and alerted the relevant authorities. The ICO investigation will nevertheless be able to consider whether the controls in place before the incident were appropriate for the sensitivity and volume of the information being handled.
Regulators may examine how Revolut authenticated government representatives, whether supporting legal documentation was independently validated, whether requests were subjected to human or legal review and whether exceptionally sensitive disclosures required additional approval.
The investigation could also consider data minimisation. Even when a government request is genuine, an organisation should normally disclose only the information that is legally required and relevant to the request. Large collections of identity, account and transaction data should not be released merely because they have been requested from a seemingly legitimate address.
The outcome will depend on evidence that has not yet been made public. The existence of a breach does not automatically establish a violation of data-protection law, and Revolut will have an opportunity to explain its procedures, the deception used by the attackers and the measures taken after detection.
Email domains must not function as proof of authority
The central security lesson extends well beyond Revolut.
Government and law-enforcement email systems are high-value targets because control of an official mailbox can allow an attacker to borrow the institution’s identity. Messages may pass conventional domain-authentication checks because they are genuinely sent through authorised government infrastructure.
Technologies such as SPF, DKIM and DMARC can help organisations detect forged email, but they are not designed to determine whether the person controlling a legitimate account is acting lawfully. A message from a compromised official mailbox may pass every technical email-authentication check.
Organisations handling official data requests therefore need controls that do not rely solely on the sender’s address or the appearance of attached documents. Requests should be authenticated through established government portals where possible, and the identity and authority of the requesting official should be independently confirmed.
High-risk requests should also be verified through a second channel using contact information obtained from an authoritative directory rather than information supplied in the incoming email. Calling a telephone number included in a fraudulent message simply allows the attacker to control both sides of the verification process.
Other safeguards can include cryptographic signatures, pre-registered agency contacts, strict approval workflows, legal review, anomaly detection and restrictions on unusually broad requests. Companies should also examine whether the named official has previously submitted requests, whether the jurisdiction matches the customer or investigation, and whether the requested information is proportionate to the stated purpose.
Requests involving emergency circumstances require speed, but urgency should trigger a specialised verification process rather than the suspension of security controls.
What affected Revolut customers should do
Customers who received a notification should assume that future communications may contain accurate personal information taken from the disclosed records. The presence of an account number, address, transaction description or identity detail does not prove that a caller or sender represents Revolut.
Affected individuals should access their accounts only through the official Revolut application or a manually entered web address. They should not follow login links or telephone numbers contained in unexpected messages, even where the communication appears to know details about their account.
Any request to move money, disclose a passcode, approve a new device, install remote-access software or transfer cryptocurrency should be treated as suspicious. Genuine bank employees and law-enforcement officials should not instruct customers to place funds in a “safe account.”
Customers should also monitor their credit files and accounts for unfamiliar applications or transactions, strengthen the security of their email and mobile accounts, and use unique passwords with multi-factor authentication wherever possible.
Because identity documents may have been exposed, affected customers may also want to contact the issuing authority for guidance on whether a document should be replaced or flagged. The appropriate response will depend on the document, the jurisdiction and the specific information listed in the individual breach notification.
Revolut faces scrutiny as its global footprint expands
The breach arrives at a sensitive time for Revolut as the London-headquartered company continues to expand internationally. Revolut says it now serves more than 80 million customers globally, including approximately 13 million in the UK.
Its scale makes the incident important even though the number of people reportedly affected represents a very small proportion of its total customer base. Banks and fintech companies hold unusually complete records of their customers, combining verified identity information with addresses, communication details, financial behaviour and transaction histories.
That concentration of information makes procedural security just as important as network security. An institution can have strong encryption, fraud detection and access controls yet still disclose sensitive records if its process for responding to trusted external authorities can be manipulated.
Revolut’s systems and customer balances may have remained untouched, but the incident demonstrates that a legitimate-looking request can sometimes achieve what an attacker might otherwise need a major technical breach to obtain.
The immediate questions concern how many customers were affected, which government domain was used, how the fraudulent requests passed Revolut’s controls and whether the criminals still possess unpublished copies of the data.
The broader question is whether financial institutions and technology companies have sufficiently adapted their disclosure procedures to a threat environment in which official email accounts, legal templates and government identities are themselves criminal commodities.