
The process banks use to receive and respond to government requests for customer information have become the centre of a serious data breach at Revolut.
The British digital bank has confirmed that an unauthorised third-party used an email address from a legitimate government agency domain to send fraudulent information requests. Revolut treated the requests as genuine and disclosed sensitive customer records.
About 680 customers were affected, according to people familiar with the investigation cited by the Financial Times, but Revolut has only described the number as “very limited.”
The exposed files reportedly included passports, driving licences, identity verification selfies, home addresses, phone numbers, bank account details and full transaction histories, including Bitcoin activity.
A Genuine Address Carried a False Request
The attackers did not need to break into Revolut’s banking systems, as they merely approached the company through an email channel that appeared to belong to a real government body with the authority to request customer information. And Revolut has not identified the agency.
However, the Financial Times reported that the hackers claimed they had compromised an Italian government email system and posed as law enforcement officers. And according to messages the alleged attackers sent to the newspaper, they exchanged emails with Revolut over several months and repeatedly requested records for selected customers.
The incident shows how a trusted communication channel can become part of an attack, especially as a legitimate domain can help an email pass routine technical checks but does not prove that the person behind the message is authorised to request private records.
Passports, Selfies, and Financial Records Were Exposed
Customer notifications shared publicly by blockchain investigator ZachXBT listed identity documents, verification photographs, account statements, IBANs, withdrawal records, and transaction histories among the exposed data. Names, occupations, dates of birth, and contact details were also reportedly included.
Together, these records can create far greater risks than the exposure of one password or account number. Muhammad Yahya Patel, a cybersecurity adviser at Huntress, described the collection as a “complete identity theft kit” because it could help criminals impersonate victims, open fraudulent accounts, or build convincing scams.
Some victims may also face personal safety concerns. The Financial Times reported that the attackers selected people they believed held significant cryptocurrency assets.
Mark Karpelès, the former chief executive of collapsed crypto exchange Mt. Gox, said his home address was among the leaked information. “I have kids, we’re living together. My address is in those files,” he told The Guardian.
Revolut Blocks the Address as Regulators Investigate
Revolut said it blocked the email address after detecting the scam and alerted the government agency, law enforcement, data protection authorities, and financial regulators. The company has also contacted affected customers and said its systems and customer funds remain secure.
In addition, The UK Information Commissioner’s Office is assessing the incident after receiving a report from Revolut.
However, a group claiming responsibility later posted a $3 million ransom demand payable in Monero, although Revolut said it had received no direct demand from the group.
For banks and technology companies, the breach exposes a difficult weakness in data request procedures. When official accounts can be compromised, checking the sender’s domain is only a minute part of verification. Requests for passports and detailed financial records also need independent confirmation through a separate, trusted channel before any information leaves the company.
Revolut will have to build up a new, strong system after this case.
