Revolut discloses data breach after fraudsters impersonated a government agency to extract customer KYC data

Revolut disclosed on September 12 that fraudsters impersonating a government agency tricked the fintech into handing over sensitive customer data, including copies of passports, driving licenses, facial verification selfies, and full transaction histories. Unlike most fintech breaches this year, no server was hacked and no password was stolen — the attacker simply asked, using a stolen but genuine-looking government email account.
The incident illustrates a growing category of fraud that security teams call “trusted-channel abuse”: rather than breaking into a system, an attacker compromises or spoofs a channel a company already trusts — in this case, official law-enforcement data requests — and lets the target's own compliance process do the work of exfiltration.
How the fraud worked
According to Revolut and reporting from TechCrunch, an unauthorized third party gained access to, or convincingly spoofed, an email account belonging to a legitimate government agency. Financial institutions routinely receive and act on data requests from law enforcement and regulators as part of standard compliance obligations, and Revolut's review process did not catch that this particular request was fraudulent before it was processed.
The fraudulent request resulted in the disclosure of full names, dates of birth, postal and email addresses, phone numbers, and occupations for a group of customers. More seriously, the attacker also obtained copies of government-issued identity documents — passports and driving licenses — along with the facial verification selfies customers submit during Revolut's identity checks. Financial records including account statements, IBANs, transaction histories, and withdrawal details were also exposed, with the disclosed data reportedly including cryptocurrency transaction history.
Who was targeted
Revolut has confirmed only that a “limited number” of customers were affected and has not disclosed an exact figure or said whether the incident was geographically concentrated. Crypto investigator ZachXBT, who reviewed details of the incident, assessed that the pattern of exposed data — KYC documents paired with detailed Bitcoin transaction histories — points to a targeted operation aimed at building profiles of high-net-worth individuals, rather than a broad, indiscriminate data grab.
That distinction matters. A targeted breach against wealthy crypto holders carries a different threat model than a mass consumer leak: the follow-on risk is less about mass phishing and more about physical security, extortion, and highly personalized social-engineering attacks against specific individuals whose wealth and identity are now both confirmed and documented.
Revolut's response
Revolut says it identified the fraudulent scheme and blocked the compromised email address, then notified affected customers directly. The company also alerted the government agency whose identity was misused, along with law enforcement and financial regulators. Revolut maintains that its core systems, infrastructure, and customer funds were not compromised — the incident is being characterized purely as a social-engineering failure in the data-request review process, not a technical breach.
Why this matters beyond Revolut
Every regulated financial institution operates a similar pipeline: law enforcement and government bodies can compel disclosure of customer data, and companies build internal processes to verify and fulfill those requests quickly, because delays carry their own legal risk. That urgency-versus-verification tension is exactly what this attack exploited.
Security researchers have flagged this style of attack — sometimes called “emergency data request” fraud — as a rising concern across the tech industry, including at major platforms that have separately disclosed similar attempts using compromised police and government email accounts. Revolut's incident is a reminder that KYC data, once collected to satisfy anti-money-laundering rules, becomes a concentrated, high-value target precisely because it links a real identity to a real financial history in one place. Financial institutions and any company that fields law-enforcement data requests should treat out-of-band verification of the requesting official — a callback to a known number, not a reply to the email itself — as mandatory, not optional.
Originally reported by TechCrunch. Read the original article for additional details.
View original source