Revolut, the digital bank, has admitted it fell victim to a phishing scam from using a legitimate government email domain that tricked the firm into leaking highly sensitive customer information.
Among the customer data includes personal details such as names, birth dates, and addresses, as well as passports, driver’s licenses, and photos used for facial verification.
It also leaked account information such as statements, IBANs, transaction history, wallet numbers, and withdrawal records.
Revolut said that customer funds and its own internal systems have not been impacted by the leak. It took action to block the email used in the phishing attak, and notified relevant authorities.
The phishing attack originated from an unathorised email account that had a legitimate government domain which remains unnamed, according to reports from Reuters.
The valid domain credentials meant that the phishing email was able to bypass typical fraud detectors.
Revolut says it has informed affected customers warning them of the information shared due to the leak, which can act as easy fodder for a range of further phishing attacks and could enable malicious actors to create fraudulent accounts.
“Trust as a security failure, not a technology failure. That’s the real story in Revolut’s breach, and it should worry every CISO reading it,” Patricia Titus, Field CISO at Abnormal AI, said.
Recommended reading
- Are You Ready for a Dark Web Data Leak?
- Revolut Posts Record £1.7Bn Profit As Retail Customers Soar
- Report: Phishing Clicks Surged 190% in 2024
- How Worried Are Brits About AI-Fuelled Phishing?
“The company handed over passports, selfies, IBANs, and Bitcoin transaction histories because one email came from inside a real government domain and passed every authentication check. No malware. No stolen credentials. Just a request that looked legitimate and a process built to comply once it did.
“This is the gap most security programs still don’t close. SPF, DKIM, and DMARC confirm a message came from where it claims to. They say nothing about whether the request itself makes sense. A compromised account sending an unprecedented ask is not a domain problem, it’s a behavioural one. Catching it requires understanding what normal looks like for that sender, then flagging the moment it isn’t.
“Digital signatures on government requests have been proposed for years and mostly ignored. They still wouldn’t stop a compromised account operating inside legitimate infrastructure. Behavioural detection and process discipline have to fill that gap together.
“A password resets in a minute. A passport doesn’t.”





