Revolut Exposes Customer Data After Fraudulent Government Requests
How the Impersonation Bypassed Security Checks
Revolut confirmed it shared sensitive customer data with an unauthorized party after fraudulent requests appeared to come from a legitimate government agency. The incident occurred when attackers used a spoofed email domain mimicking an official authority to trick the fintech firm into releasing personal information. Revolut described the breach as a sophisticated impersonation scam, emphasizing that its internal systems were not compromised and no malware or hacking tools were involved.
Breaking news:
The fraudsters exploited trust in official channels by sending requests that closely resembled genuine government inquiries, complete with authentic-looking email addresses and formal language. Revolut stated it verified the requests through standard procedures but failed to detect the deception due to the high level of sophistication in the spoofing. The exposed data included names, contact details, and transaction histories, though the company said no passwords, PINs, or payment card information were compromised. Revolut has since notified affected customers and reported the incident to relevant data protection authorities.
What Steps Are Being Taken to Prevent Future Incidents?
The attackers did not hack Revolut’s systems but instead manipulated human verification processes by impersonating a government entity. Revolut explained that its team followed internal protocols for handling official data requests, which typically involve validating the sender’s authority. However, the fraudulent emails used a domain that closely resembled a real government address, making visual detection difficult without advanced email authentication tools. The company admitted that while procedures were followed, they were insufficient to catch this level of deception. Revolut has begun reviewing its verification workflows and exploring enhanced email security measures, including stricter domain validation and multi-layered approval for sensitive data disclosures.
Revolut said it is working with cybersecurity experts to strengthen its defenses against social engineering and impersonation attacks. The firm is implementing additional verification steps for government data requests, including direct contact with agencies through known, secure channels. It is also investing in employee training focused on recognizing sophisticated phishing and spoofing attempts. Regulatory bodies are reviewing the case to determine whether Revolut met its obligations under data protection laws. The company stressed that customer trust remains its priority and that it is committed to transparency throughout the ongoing investigation.
Was Revolut’s system hacked in this incident? No, Revolut confirmed there was no breach of its internal systems or networks. The data exposure resulted from a successful impersonation scam where attackers tricked staff into believing they were responding to a legitimate government request.
Frequently Asked Questions
What customer information was exposed? The shared data included names, email addresses, phone numbers, and limited transaction details. Revolut stated that sensitive financial data such as passwords, PINs, and full payment card numbers were not accessed or disclosed.
Is Revolut taking responsibility for the incident? Yes, Revolut has acknowledged the error, notified affected users, and reported the event to data protection regulators. The company said it is cooperating fully with investigations and improving its safeguards to prevent recurrence.
More stories: