LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

Revolut Discloses Customer Data Exposure Following Fraudulent Government Agency Email

Cointelegraph · Michael Millard

Financial technology firm Revolut revealed that sensitive customer data, including passport copies, verification selfies, and full transaction histories, was exposed due to a fraudulent request impersonating a government agency. Requests, sent from a legitimate government email domain and passing Revolut's authentication, were later identified as unauthorized. Revolut promptly informed impacted customers and relevant authorities, assuring that their systems and client funds remained secure.

Details of the Incident and Fraud Detection

Financial technology company Revolut encountered a sophisticated external impersonation scam involving an unauthorized party using a legitimate government agency email domain to submit fraudulent customer data requests.

The requests, originating from a domain belonging to an actual government agency, initially passed Revolut's authentication checks. However, subsequent investigations revealed that these requests were unauthorized.

On Friday, Revolut notified customers whose information might have been compromised through this fraudulent activity.

Revolut’s Response and Follow-Up Actions

A company spokesperson explained that upon detection, Revolut immediately blocked the suspicious email address and alerted the relevant government agency involved.

Additionally, law enforcement and financial regulatory authorities were informed to facilitate investigations and help prevent future incidents.

Revolut emphasized that their systems and customer funds remained unaffected and that they were in direct contact with the limited number of impacted users to offer support.

Community Reaction and KYC System Criticism

Crypto investigator ZachXBT suggested the breach was likely limited in scope and targeted high-net-worth individuals specifically.

Discussions and critiques of mandatory Know Your Customer (KYC) processes surfaced on social media, notably on X, where users debated the effectiveness and risks of extensive data sharing.

Among commentators, Marc Zeller stated he woke up to find all his data leaked by Revolut, criticizing the KYC system for not delivering meaningful benefits while exposing many users to harm.

Why it matters

This incident highlights the vulnerabilities in fintech customer verification systems, illustrating how even robust authentication checks can be circumvented through social engineering and domain spoofing of official government emails. Revolut’s case underscores the critical challenges financial companies face when responding to government and regulatory data requests, particularly the risks related to large-scale exposure of sensitive client information. The criticism of the KYC system voiced in community discussions reflects ongoing debates about balancing security, privacy, and efficiency in digital identity verification processes today.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗