The breach began when an unauthorized party sent Revolut fraudulent requests for customer information, using an email address that appeared to come from a real government agency. Because the email passed every normal check, Revolut staff treated the requests as real and handed over sensitive records, including customers’ identity documents, addresses, phone numbers, verification photos, account statements, and transaction histories. No malware or stolen passwords were used in the attack as it relied fully on impersonating a trusted source.
A spokesperson from Revolut commented:
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information. Revolut systems and customer funds are unaffected.”
Revolut has since blocked the fraudulent email address and confirmed it has contacted the customers affected. The company reported the incident to the relevant government agency, along with law enforcement and financial regulators, and said customer funds and its own systems weren’t affected. So far, Revolut has reached out to around 680 customers to warn them their data may have been exposed, including many well-known business figures, athletes, and performers.
How the attackers gained access
Security experts say the case shows a weakness in how financial companies verify sensitive requests.
Patricia Titus, Field CISO at Abnormal AI, explained:
“The company handed over passports, selfies, IBANs, and Bitcoin transaction histories because one email came from inside a real government domain and passed every authentication check. No malware. No stolen credentials. Just a request that looked legitimate and a process built to comply once it did.”
Muhammad Yahya Patel, vCISO and cybersecurity adviser at Huntress, added:
“For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question isn’t why an attacker tried this. It’s why a regulated financial institution handling highly sensitive data didn’t have sufficiently rigorous verification controls to catch it.”
Stolen data appears online as ransom threat grows
Samples of the stolen data have already appeared on Telegram, where the attackers are threatening to release more of it every day unless Revolut pays the ransom. In the Netherlands, broadcaster BNR reported that some of the leaked files included Dutch passport copies, among them one belonging to singer Yade Lauren. However, Revolut hasn’t said how many Dutch customers were affected. Additionally, the hackers have posted details of other public figures like the CEO of Gamdom, Felix Römer, and tennis player Alexander Shevchenko.
The breach comes at a sensitive time for the company as Revolut has been expanding into new markets including France, Mexico, India, and the UAE, and recently received conditional approval to open a national bank in the United States. The fintech said its investigation into the breach is still ongoing.
