Site navigation

Revolut Leaked Customer Data to Fake Government Email Account

Elizabeth Greenberg

,

revolut leak
Revolut seemed to give the personal and sensitive customer data over to the fake government email willingly. 

Revolut, the digital bank, has admitted it fell victim to a phishing scam from using a legitimate government email domain that tricked the firm into leaking highly sensitive customer information.

Among the customer data includes personal details such as names, birth dates, and addresses, as well as passports, driver’s licenses, and photos used for facial verification.

It also leaked account information such as statements, IBANs, transaction history, wallet numbers, and withdrawal records.

Revolut said that customer funds and its own internal systems have not been impacted by the leak. It took action to block the email used in the phishing attak, and notified relevant authorities.

The phishing attack originated from an unathorised email account that had a legitimate government domain which remains unnamed, according to reports from Reuters.

The valid domain credentials meant that the phishing email was able to bypass typical fraud detectors.

Revolut says it has informed affected customers warning them of the information shared due to the leak, which can act as easy fodder for a range of further phishing attacks and could enable malicious actors to create fraudulent accounts.

“Trust as a security failure, not a technology failure. That’s the real story in Revolut’s breach, and it should worry every CISO reading it,” Patricia Titus, Field CISO at Abnormal AI, said.


Recommended reading


“The company handed over passports, selfies, IBANs, and Bitcoin transaction histories because one email came from inside a real government domain and passed every authentication check. No malware. No stolen credentials. Just a request that looked legitimate and a process built to comply once it did.

“This is the gap most security programs still don’t close. SPF, DKIM, and DMARC confirm a message came from where it claims to. They say nothing about whether the request itself makes sense. A compromised account sending an unprecedented ask is not a domain problem, it’s a behavioural one. Catching it requires understanding what normal looks like for that sender, then flagging the moment it isn’t.

“Digital signatures on government requests have been proposed for years and mostly ignored. They still wouldn’t stop a compromised account operating inside legitimate infrastructure. Behavioural detection and process discipline have to fill that gap together.

“A password resets in a minute. A passport doesn’t.”

Elizabeth Greenberg

Staff Writer

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences