Revolut Customer Data Exposed After Fake Government Request: Why Trusted Emails Still Need Verification
Revolut has disclosed that customer information was provided to an unauthorised third party after fraudulent requests appeared to originate from a legitimate government agency email domain.
The incident is unusual because the communication was not simply sent from a convincing lookalike address. According to Revolut, the request originated from an unauthorised email account operating within an official government agency domain, which led the company to believe that it was genuine.
Potentially disclosed information included personal identification data, copies of identity documents, account information and transaction histories.
Revolut has said that its own systems were not compromised and that customer funds were unaffected.
The incident highlights an important cyber security principle: an email can originate from a trusted domain and still require independent verification.
What Happened?
Revolut said an unauthorised third party submitted fraudulent requests for customer information using an email account associated with a legitimate government agency domain.
The company subsequently discovered that the request was not authentic and blocked the email address.
Revolut also notified the relevant government agency, law enforcement, data protection authorities and financial regulators.
The company has described the incident as a sophisticated external impersonation scam and said that only a limited number of customers were affected.
It has not publicly identified the government agency involved or disclosed the total number of affected customers.
What Information May Have Been Disclosed?
According to notifications sent to affected customers, potentially disclosed information included:
- Names.
- Dates of birth.
- Postal addresses.
- Email addresses.
- Telephone numbers.
- Passport or driving licence copies.
- Verification photographs.
- Account statements.
- Transaction histories.
- IBAN information.
- Withdrawal records.
Some affected customers were also informed that cryptocurrency transaction information may have been included.
The sensitivity of these records means the potential consequences extend beyond inconvenience. Identity documents, transaction histories and personal information can provide criminals with material that may support subsequent impersonation, phishing or social-engineering attempts.
Why a Genuine Email Domain Can Still Be Dangerous
Many organisations rely heavily on email-domain verification when assessing whether a request is genuine.
If a message comes from an official government, supplier or customer domain, it can appear significantly more trustworthy than an email from an unfamiliar address.
However, a legitimate domain does not guarantee that the individual using the account is authorised.
An attacker may gain access to an email account through credential theft, compromised infrastructure or another form of unauthorised access.
This creates an important distinction between authentication and verification.
Authentication may help establish where a message originated. Verification establishes whether the person making the request is authorised and whether the request itself is legitimate.
Organisations dealing with sensitive information need both.
Why Independent Verification Matters
One way to reduce this type of risk is to verify sensitive requests through a separate communication channel.
Where an organisation receives an unusual request by email, verification could involve contacting the requesting organisation using independently established contact details rather than replying directly to the original message.
The aim is to confirm:
- The requesting person is genuine.
- The request has been authorised.
- The information requested is appropriate.
- The proposed method of disclosure is secure.
This becomes particularly important where requests involve identity documents, financial information or other highly sensitive records.
Sensitive Data Requests Require Greater Scrutiny
Not every email needs secondary verification.
Controls should reflect the sensitivity of the request and the consequences of getting the decision wrong.
Organisations should consider whether internal procedures clearly define:
- Which requests require additional approval.
- Which types of data are particularly sensitive.
- How official requests are independently verified.
- Who has authority to release information.
- How unusual or urgent requests should be escalated.
- How evidence of the verification process is retained.
A structured process reduces reliance on an individual employee simply deciding whether an email looks genuine.
Social Engineering Is Becoming More Convincing
Social engineering attacks frequently succeed because they exploit trust rather than technical vulnerabilities.
Attackers may impersonate:
- Government agencies.
- Senior executives.
- Customers.
- Suppliers.
- Banks.
- Professional advisers.
- Law enforcement.
- Internal IT teams.
Where an attacker can communicate through an authentic or compromised account, the message may contain many of the indicators employees have traditionally been taught to trust.
This means awareness training needs to move beyond simply checking the sender's domain or looking for spelling mistakes.
Modern social-engineering attacks can be considerably more sophisticated.
The Risk of Secondary Fraud
When sensitive customer information is disclosed, the original incident may not be the end of the risk.
Personal data can potentially be used to make future fraud attempts more convincing.
A criminal who knows an individual's name, address, account details or transaction history may be able to create highly personalised communications.
For example, subsequent contact could reference genuine transactions or personal details in an attempt to persuade the victim to disclose further information or transfer funds.
This is why individuals affected by a data incident should be particularly cautious about unexpected contact that appears to reference genuine account activity.
What Organisations Should Review
The Revolut incident provides a useful opportunity for businesses to review how they handle sensitive information requests.
Important questions include:
- Are official requests independently verified?
- Are employees permitted to rely solely on the sender's email domain?
- Are high-risk disclosures subject to secondary approval?
- Is there a documented escalation process?
- Are sensitive records transferred securely?
- Are unusual requests investigated?
- Can previous requests be audited if concerns later arise?
The objective is not to create unnecessary friction around legitimate requests.
It is to introduce additional verification where the potential consequences justify it.
Conflict International's Cyber Security specialists support organisations with cyber risk assessments, incident response and investigations where systems, information or communications may have been compromised.
Technical Controls Are Only Part of Cyber Security
Strong cyber security requires more than protecting networks from direct intrusion.
Organisations also need processes capable of identifying situations in which trusted systems or communications are being misused.
In the Revolut case, the company says its own systems were not breached.
Instead, the issue arose because an apparently legitimate external communication was relied upon when sensitive information was released.
That distinction matters.
A business can have effective firewalls, access controls and malware protection and still suffer a significant security incident if an attacker successfully manipulates internal processes.
Trust Should Still Be Verified
The Revolut incident demonstrates why organisations handling sensitive information should not treat the appearance of authenticity as conclusive proof.
A legitimate domain can be compromised. An authorised-looking account can be misused. A request can pass technical checks and still be fraudulent.
For organisations holding personal, financial or commercially sensitive information, the strongest defence combines technical controls with proportionate human verification.
If your organisation has experienced a suspected cyber incident, data exposure or sophisticated impersonation attempt, Conflict International can help establish what happened, identify potential vulnerabilities and support an appropriate response. Contact our team to discuss your requirements in confidence.