Revolut Confirms Sensitive Customer Data Exposed in Fraudulent Government Domain Spoofing Incident
UK-based fintech company Revolut has confirmed that sensitive customer data was exposed to an unauthorized third party following an advanced social engineering breach. The incident occurred after company personnel responded to fraudulent data disclosure requests originating from what appeared to be a legitimate government email domain.
A Revolut spokesperson confirmed to Reuters that the breach was detected post-incident. The company immediately blocked the compromised email address, launched an internal investigation, and notified the affected government agency, law enforcement authorities, data protection watchdogs, and financial regulators.
Scope of Compromised Customer Data
According to an initial report by TechCrunch, the unauthorized party accessed a broad array of personally identifiable information (PII) and Know Your Customer (KYC) records, including:
Personal Information: Dates of birth, residential mailing addresses, email addresses, and phone numbers.
Government-Issued Identification: Scanned copies of passports, national identity cards, and driver's licenses.
Account Records: Select reports suggest additional account-level metadata may have been accessed for certain users.
Revolut has not disclosed the precise number of impacted customers or the total volume of compromised records, but confirmed that direct notifications to affected account holders are underway.
Customer Funds and Core Systems Uncompromised
Revolut emphasized that core transactional systems and customer funds were not breached or affected by the incident. The company maintains that its banking architecture remains secure and that the exposure was isolated to the fraudulent document requests.
Sophisticated Impersonation Vector
The incident underscores escalating risks associated with advanced domain spoofing and institutional impersonation. Rather than utilizing generic phishing links or easily detectable lookalike domains, the attacker leveraged or compromised an authentic government email domain to bypass standard verification protocols, lending credibility to the fraudulent data requests and exploiting administrative compliance procedures.














