Skip to main content
Emerging ThreatsData Breaches

Revolut Breach Exposes Sensitive Customer Data via Fake Government Requests

Concerned person in office setting handles customer inquiry near computer.

"a sophisticated external impersonation scam," Revolut said.

Revolut's account of the incident

On September 14, Revolut confirmed to Infosecurity that an unauthorized third party submitted "fraudulent requests for information" to the company using "a legitimate government agency domain email." Revolut described the technique as "a sophisticated external impersonation scam" and said the requests carried valid technical domain authentication. Staff fulfilled those requests under standard legal-compliance procedures, which led to sensitive customer information being disclosed.

Data exposed, as reported by an independent researcher

Independent crypto-security researcher ZachXBT posted a warning on Telegram on September 12, sharing a Revolut customer notification that had been sent the previous day. According to the reporting and the material shared by ZachXBT, the compromised records include full names, dates of birth, residential addresses, phone numbers, email addresses and occupations; copies of government ID documents such as passports and driver's licenses; and verification selfies.

ZachXBT also reported that financial details were exposed, including IBANs, account-opening dates, complete transaction and withdrawal histories and Bitcoin wallet reference numbers. Revolut has not provided a detailed public accounting of which specific records were accessed beyond the notification shared by the researcher.

Security reactions: Huntress and CyberSmart

Muhammad Yahya Patel, vCISO & cybersecurity advisor at Huntress, framed the incident as a failure of verification controls for a firm that relies on digital identity. "For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high," Patel said. He asked why a regulated financial institution handling highly sensitive data "didn't have sufficiently rigorous verification controls to catch it."

Jamie Akhtar, CEO and co‑founder of CyberSmart, cautioned that even though Revolut said customer funds and its systems were unaffected, the exposed information could be used for identity fraud and highly targeted phishing attacks. Patel added that the range of data allegedly exposed "go well beyond a standard data breach notification," calling the package "a complete identity theft kit handed to whoever sent those fraudulent requests."

Revolut's immediate steps and notifications

Revolut said its security team "immediately blocked the address" on discovery, notified affected customers and alerted the relevant government agency as well as enforcement agencies, data protection and financial regulators. The firm emphasized that its systems and customer funds were untouched. Revolut declined to comment further on the number of affected customers or whether the breach affected any specific market or department.

What this means for customers, security teams, and regulators

  • Customers: Affected users were advised to be especially wary of unexpected calls, emails or messages claiming to come from Revolut, government bodies or other trusted organisations. Jamie Akhtar recommended never disclosing passwords, passcodes or one‑time security codes and to contact Revolut only through its official app or verified website. He also urged enabling multi‑factor authentication (MFA), using unique passwords, monitoring accounts and credit reports, and promptly reporting suspected identity misuse.
  • Security teams: The incident highlights a vector—fraudulent requests authenticated with what appeared to be a legitimate domain address—that will demand sharper verification controls where legal or regulatory requests are processed. Huntress' Patel explicitly questioned why verification controls did not catch the impersonation despite technical authentication.
  • Regulators and law enforcement: Revolut said it notified the "relevant government agency" and enforcement, data protection and financial regulators; those bodies will now have the disclosures and the company's follow-up actions to assess compliance and any regulatory implications.

Two clear facts frame the immediate aftermath: Revolut says only a "very limited group of customers" were affected and that systems and customer funds were untouched, while an independent researcher has published a customer notification suggesting highly sensitive identity and financial records were accessed. Revolut's decision not to disclose the number of affected customers or the markets involved leaves the exact scale unresolved even as affected users are urged to take defensive steps and regulators have been notified.

Original story