Revolut Exposes Customer Data After Fraudsters Exploit Government Email Domain
- Revolut said an unauthorised third party used a legitimate government agency email domain to send fraudulent requests, exposing data on a “very limited” number of customers.
- The disclosed information may have included passports and driver’s licences, verification selfies, contact details, IBANs, account statements and full transaction histories, including Bitcoin activity.
- Revolut said its systems and customer funds were unaffected, that it blocked the fraudulent email and alerted the agency, law enforcement and regulators, but has not named the agency or said how many customers were hit.
British fintech Revolut confirmed this week that fraudsters used a legitimate government agency email domain to submit fraudulent requests for information, drawing the company into disclosing personal and financial data belonging to a limited number of its customers.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information”, the company said in a statement.
Firms like Revolut routinely field data requests from government agencies and law enforcement, and because these arrived from a genuine government domain, they cleared the checks Revolut runs on that agency’s mail rather than tripping the defences that catch spoofed senders.
The company said it blocked the email address once it spotted the scam and alerted the agency, law enforcement and financial regulators.
Read more: Visa Brings Onchain Lending to Payment Settlement
The data that may have been handed over included customers’ names, dates of birth, occupations, postal and email addresses and phone numbers, copies of identity documents such as passports and driver’s licences, and verification selfies.
It also covered financial records: IBANs, account status, account opening dates, wallet reference numbers, withdrawal records, account statements and full transaction histories.
For crypto holders, that last category included Bitcoin transaction histories, the detail that pushed the incident in front of Revolut’s crypto users. Revolut said no biometric facial telemetry was involved or compromised, and that its own systems and customer funds were unaffected.
The exposure came to light after ZachXBT, a blockchain investigator known for tracing crypto theft, posted a copy of the notification Revolut had sent to affected users. Revolut said it had contacted those customers directly.
Read more: Germany Plans 25% Crypto Tax on New Investments From 2028
Numbers Revolut Won’t Give
Revolut called the affected group “very limited” but has not said how many customers were caught up in the scam, or which government agency’s domain the fraudsters used, citing the continuing investigation.
It also has not said when the fraudulent requests were made or over what period customer records flowed out. The gaps sit against the company’s scale. Revolut fully opened its app to Australians after clearing a long waitlist and runs a crypto exchange for Australian users, part of an APAC push that has added millions of accounts holding exactly the identity documents and transaction records this scam sought.