Fintech firm Revolut has revealed a novel data breach involving impersonated government email requests that led to unauthorized disclosure of highly sensitive customer data. Rather than a typical hack, the attacker submitted fraudulent requests using an email address registered under the domain of a legitimate government agency. Revolut claims its app and core systems were untouched, and that customer funds remain secure.
How the Deception Worked
The incident exploited domain authentication. An email, originating from an unauthorized address under what appeared to be an official government domain, carried valid credentials (such as SPF, DKIM, or DMARC) that convinced Revolut staff to treat it as genuine. Seeing the request as legitimate under established policies, Revolut released sensitive customer information via its formal disclosure process.
What Was Exposed
The stolen records included full names, birth dates, occupations, postal addresses, email addresses, and phone numbers. Document-verification materials—passport or driving-license scans, plus facial images submitted during onboarding—were also accessed, though biometric facial telemetry was reportedly unaffected. Financial disclosures potentially divulged IBANs, account opening dates, transaction histories (including cryptocurrency), withdrawal info, and wallet reference numbers.
Revolut says only a “limited” number of users were impacted and has reached out directly to those affected. However, key details remain undisclosed: the precise number of customers, the agency whose domain was misused, the geographic span of impacts, the extent of successful fraudulent requests, and how long the breach went undetected.
Alleged Scale and Response
A crypto sleuth known as ZachXBT reported that high-net-worth users were likely targeted. A threat actor calling itself “IAmNotAVillain” claims to have compromised several Italian law-enforcement agencies and collected 147 GB of data from Italian Revolut customers over six months. These allegations haven’t been independently confirmed.
Revolut says it has blocked the fraudulent email address, informed the affected agency, and notified regulators, law enforcement, and relevant supervisory bodies. It also emphasized that no systems or financial assets were breached. Still, the exposure of legal IDs and financial histories poses a meaningful downstream risk.
Lessons and Preventive Measures
This breach spotlights weak points in financial-sector workflows for government requests. While domain authentication is helpful, it isn’t sufficient—especially if malicious actors compromise valid government inboxes. Stronger safeguards are needed: registered agency contacts, case numbers, multiple levels of authorization, request anomaly detection, minimal data disclosure, and tamper-evident logs.
For customers, the risks include identity theft, phishing, SIM-swapping, bank impersonation, or extortion. Revolut users are advised to verify communications using the company’s app, secure their email and phone accounts, monitor statements and credit reports, and report any suspicious or fraudulent activity promptly.
The attack shows that even trusted digital paths can be weaponized. Revolut says it’s investigating. Key open questions include identifying the compromised agency, clarifying how long the abuse lasted, and determining the total scope of customers affected.
It’s a stark reminder: in cybersecurity, established authority doesn’t eliminate the need for scrutiny. Organizations must treat authenticated requests as one signal—not the ultimate proof—and build in robust checks. The ultimate test will be how companies adjust policies going forward to prevent similar breaches.