Pull to refresh
Logo
Revolut tricked into releasing customer data via fraudulent government requests

Revolut tricked into releasing customer data via fraudulent government requests

Force in Play

An attacker using a legitimate government email domain obtained passports, selfies, and Bitcoin transaction histories

Today: Media confirms Revolut fell for fraudulent government requests

Overview

Updated 1 hour ago

An attacker sent Revolut a data request from a legitimate government email domain. The fintech's compliance team compiled the requested customer records and transmitted them.

The request passed email authentication checks because the attacker controlled a real mailbox inside the agency's infrastructure. Revolut discovered the fraud only after contacting the agency separately. Affected customers' passports are now linked to their Bitcoin transaction histories, and that link cannot be reversed.

Why it matters

Passports linked to Bitcoin wallet histories are in an attacker's hands—an exposure no password reset can reverse.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

Limited
Number of customers affected
Revolut declined to disclose the exact count of impacted individuals
80M+
Revolut's global customer base
The fintech operates as a bank in more than 30 countries
$200B
Potential listing valuation
Reported value of a possible public listing, up from a $75B private valuation

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

2 events Latest: Today
  1. Media confirms Revolut fell for fraudulent government requests

    Today Publication

    TechCrunch, Bloomberg, and Reuters report the breach. The fraudulent email passed SPF, DKIM, and DMARC authentication, indicating the attacker controlled a mailbox inside the real agency domain.

  2. Revolut notifies affected customers of data disclosure

    Statement

    Revolut emails customers warning that identity documents, selfies, and transaction histories were disclosed to an unauthorized third party via fraudulent government requests. ZachXBT publicizes the notification.

Scenarios

1

FCA opens investigation into Revolut's data request handling

Possible Resolves by Mar 1, 2027

Discussed by: UK financial regulators, compliance analysts

Revolut already alerted data-protection officials and financial regulators about the breach. A formal probe would examine whether the company had adequate verification procedures for government data requests before releasing customer records. Fines or mandated process changes could follow if gaps are found.

2

Compromised government agency publicly identified

Possible Resolves by End of 2026

Discussed by: Mark Karpelès, crypto security researchers

Karpelès argued that naming the agency would let other banks and exchanges audit whether they received similar fraudulent requests. If Revolut or the agency goes public, other institutions would check their request logs. The attacker may have targeted multiple firms through the same compromised mailbox.

3

Regulators mandate out-of-band verification for data requests

Uncertain Resolves by Q2 2027

Discussed by: ETHNews, compliance industry observers

The breach exposed a gap: email authentication alone cannot verify a government request's legitimacy. Regulators could require banks and fintechs to confirm requests through a separate channel before releasing any records. That would be a structural change to how financial institutions handle government data requests.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

June 2015

US OPM data breach (2015)

Hackers compromised the US Office of Personnel Management, exposing background check files including fingerprints and security clearance data of 21.5 million current and former federal employees.

Then

The agency's leadership resigned; Congress held hearings. China was widely suspected of involvement.

Now

Established that stolen identity data creates permanent risk — fingerprints and background records cannot be reset or rotated.

Why this matters now

The Revolut breach raises the same permanence problem: passports tied to crypto holdings stay exposed no matter what the company does next.

March 2022

LAPSUS$ social engineering attacks (2022)

The LAPSUS$ hacker group used social engineering and phone-based impersonation to breach Uber, Microsoft, Nvidia, and Okta. In Uber's case, an attacker tricked an employee into approving a multifactor authentication request, gaining admin access to internal systems.

Then

Uber paid the attacker $100,000 through its bug bounty program. Microsoft and Okta disclosed separate LAPSUS$ breaches weeks later.

Now

The attacks showed that convincing impersonation of trusted roles could defeat technical security controls more effectively than exploits.

Why this matters now

Like Revolut, the breaches exploited trust in authentication processes rather than breaking encryption. The attacker weaponized a trusted channel to bypass security.

January 2024

Trezor hardware wallet breach (2024)

Trezor exposed contact and order data of more than 80,000 customers in a January 2024 breach of its support portal. No private keys were compromised, but names, emails, and addresses were leaked.

Then

Trezor confirmed the breach and warned users to watch for phishing attempts.

Now

Set a precedent that crypto firms' customer data is a target even when funds and keys remain secure.

Why this matters now

Revolut's breach similarly exposed identities without touching private keys or funds, but went further by linking those identities to Bitcoin transaction histories.

Sources

(6)