Revolut customers’ sensitive data exposed in phishing attack that fooled email security checks

1 hour ago 23

Revolut, the British fintech company eyeing a $200 billion valuation and a banking license, just gave away sensitive customer data to someone pretending to be a government official. The attacker didn’t need to hack a single system. They just sent a convincing email.

The incident, which Revolut characterized as a “sophisticated external impersonation scam,” resulted in the exposure of identity documents, verification selfies, full names, dates of birth, contact information, financial records including IBANs, withdrawal histories, and notably, Bitcoin-related transaction activity. Customer notifications began going out on September 11, 2026.

How a fake email passed every security check

The attack worked because the fraudulent data request appeared to come from a legitimate government agency’s email domain. More critically, the message passed SPF, DKIM, and DMARC checks, the trio of email authentication protocols that organizations rely on to verify a sender’s identity.

Think of those protocols as the digital equivalent of checking someone’s ID at the door. SPF confirms the email came from an authorized server. DKIM verifies the message wasn’t tampered with in transit. DMARC ties them together and tells the recipient what to do if either check fails. All three gave the green light on this one.

That meant Revolut’s compliance team had every technical reason to believe the request was genuine. So they processed it, handing over customer records to an unauthorized third party who had essentially forged a perfect set of credentials without ever touching Revolut’s internal systems.

No passwords were stolen. No PINs or private keys were compromised. No customer funds were moved. But a trove of personal and financial data walked out the door through the front entrance.

The crypto dimension makes it worse

Among the exposed records were Bitcoin transaction histories, a detail that elevates this from a standard data breach into something with more targeted risk potential. Cryptocurrency transaction data, combined with identity documents and verification selfies, gives bad actors a fairly complete toolkit for identity fraud, social engineering, or even targeted phishing campaigns against crypto holders.

Revolut described the number of affected customers as “limited,” though the company has not disclosed the exact figure. Public awareness of the breach grew as affected individuals, including notable figures from the crypto space, began sharing details of the notifications they received.

A compliance protocol vulnerability, not a technical one

What makes this breach unusual is the attack vector. This wasn’t a zero-day exploit or a compromised database. It was a social engineering attack that targeted Revolut’s compliance workflow for responding to official government data requests.

Revolut has since blocked the unauthorized email address and notified both law enforcement and relevant regulatory agencies. The company confirmed that its systems remain uncompromised and that no customer funds were affected.

Timing couldn’t be worse

The breach arrives at a particularly sensitive moment for Revolut. The company has been actively pursuing a banking license, a process that involves intense regulatory scrutiny of exactly the kind of operational controls that failed here. Revolut has also been exploring a public listing with a valuation target of around $200 billion.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article