A significant security incident has cast a shadow over Revolut, the rapidly expanding fintech giant, revealing that the company inadvertently disclosed highly sensitive customer information to an unauthorized third party masquerading as a legitimate government agency. This "social engineering" attack, devoid of complex technical breaches, underscores critical vulnerabilities in internal verification protocols and raises serious questions about data protection practices within the fast-paced neobanking sector. The compromised data, including passports, selfies, and detailed transaction histories, represents a comprehensive identity theft kit, posing severe risks to affected individuals.
The Unfolding of a Deceptive Breach
The incident came to light on Friday, September 11, when several Revolut customers began receiving notifications indicating a potential data breach. These alerts quickly caught the attention of ZachXBT, a prominent crypto investigator, who subsequently shared the information on Telegram, bringing the matter into the public domain. The rapid dissemination of the news put immediate pressure on Revolut to address the growing concerns.
The following day, Saturday, September 12, Revolut officially confirmed the breach to TechCrunch. The company acknowledged that an unauthorized entity had successfully submitted requests for customer information. Crucially, these requests originated from an email address hosted on the legitimate domain of a government agency, lending an air of authenticity that bypassed Revolut’s initial verification processes. In response to these deceptive demands, the neobank regrettably transmitted a substantial volume of customer data.
The Nature of the Compromise: A "Counter Error"
What makes this incident particularly striking is its departure from typical cyberattack methodologies. Revolut’s systems were not directly hacked, no malware was deployed, and there was no intrusion into their core infrastructure. Instead, the breach was the result of a sophisticated social engineering ploy, which the original report aptly describes as a "counter error." The perpetrator simply exploited existing, legitimate channels for information requests that financial institutions regularly receive from law enforcement, judicial bodies, or tax authorities.
The fraudulent email managed to pass standard authentication checks, such as SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail), which verify that a message indeed originates from the server it claims to. This suggests one of two scenarios: either an email account belonging to the genuine government agency was compromised, allowing the attacker to send requests from within its trusted network, or an insider at the agency was complicit in creating a specific email address for the illicit purpose. Revolut only uncovered the deception after the data had already been transmitted, by proactively re-contacting the purported requesting agency to confirm the legitimacy of the demands. This reactive discovery highlights a critical lapse in proactive verification mechanisms before sensitive data release.
Extensive Data Compromised and Its Far-Reaching Implications
The scope of the personal data handed over is alarmingly comprehensive. It includes, but is not limited to:
- Full names
- Dates of birth
- Postal and email addresses
- Phone numbers
- Copies of passports or driver’s licenses
- Selfies taken for identity verification (KYC – Know Your Customer)
- International Bank Account Numbers (IBANs)
- Complete account statements
- Full transaction histories, specifically detailing cryptocurrency transactions.
Revolut has characterized the number of affected customers as "limited" without providing a specific figure or identifying the government agency or country involved. This lack of transparency is concerning, especially given Revolut’s immense global footprint, boasting over 80 million customers across more than 30 countries. Even a "limited" number in this context could translate to thousands, or even tens of thousands, of individuals whose deeply personal and financial information is now in unauthorized hands.
The aggregation of such diverse and sensitive data components forms a potent "identity theft kit." With a passport copy, a verification selfie, a home address, and a complete financial transaction history—including cryptocurrency movements—malicious actors possess nearly everything required to impersonate an individual across various platforms and services. This significantly elevates the risk beyond simple phishing attempts, enabling more sophisticated attacks such as account takeovers, fraudulent loan applications, and severe financial fraud.
Moreover, the inclusion of cryptocurrency transaction histories is particularly alarming. As highlighted by ZachXBT and the original report, the attack may have specifically targeted high-net-worth clients, especially those dealing in Bitcoin or other digital assets. The former CEO of the infamous Mt. Gox exchange, Mark Karpelès, was among those notified, lending credence to the hypothesis of targeted wealthy individuals. The year 2025 notably saw a surge in France of kidnappings specifically targeting cryptocurrency holders. Knowledge of an individual’s crypto holdings combined with their residential address provides precisely the intelligence that such criminal enterprises seek, escalating the threat from digital fraud to physical danger.
Revolut’s Response and Transparency Concerns
Revolut’s official communication regarding the incident has emphasized that "customer systems and funds are not affected." While technically true that the core banking systems were not breached and funds remain secure within Revolut, this statement has been criticized for downplaying the gravity of the situation. The data was not exfiltrated through a system vulnerability but was voluntarily released by the bank itself, albeit under false pretenses. This distinction is crucial, as it points to a failure in operational security rather than a purely technical one.
The company’s reluctance to disclose key details—such as the exact number of affected clients, the specific country, the date the data was transferred, and critically, the name of the impersonated government agency—has fueled frustration and concern. Withholding the agency’s name prevents other financial institutions and platforms from checking if they too have received fraudulent requests from the same email domain, thus hindering broader industry protection efforts. This lack of transparency also complicates the ability of affected individuals to assess their specific risk profile and take appropriate preventative measures.
This is not Revolut’s first encounter with significant data security challenges. In September 2022, a separate social engineering attack led to the exposure of data belonging to 50,150 customers, as confirmed by the Lithuanian regulator, under whose jurisdiction Revolut operates much of its European business. These repeated incidents underscore a pattern of vulnerability to non-technical security breaches that demand more robust internal controls and employee training.
Broader Industry and Regulatory Context
The Revolut incident echoes similar "counter error" scenarios seen in the wider tech industry. In 2022, reports from Bloomberg revealed that tech giants Apple and Meta had provided user data to cybercriminals who impersonated law enforcement officials using forged "emergency data requests." These platforms, like banks, receive thousands of such requests annually, and the sheer volume can lead to a reliance on superficial checks, often leaving the final verification to human judgment. This vulnerability highlights a systemic challenge across industries that handle vast amounts of sensitive user data and are legally obligated to respond to official requests.
From a regulatory perspective, such incidents fall under stringent data protection frameworks like the General Data Protection Regulation (GDPR) in Europe. GDPR mandates strict rules for data handling, notification requirements for breaches, and significant penalties for non-compliance. Regulators, particularly in Lithuania where Revolut is licensed for many of its European operations, will undoubtedly be scrutinizing the adequacy of Revolut’s internal processes and its adherence to data protection principles. The previous 2022 incident and subsequent regulatory findings will likely add weight to any ongoing investigations.
For the fintech industry as a whole, this event serves as a stark reminder that rapid innovation and aggressive growth must be meticulously balanced with equally robust security measures and internal controls. Neobanks, often lauded for their agility and user-friendly interfaces, frequently operate with leaner legacy systems but must still invest heavily in training their personnel to identify and thwart sophisticated social engineering attacks that exploit human trust rather than technical flaws.
Recommendations for Affected Clients and Future Outlook
For Revolut customers who received notifications about their data being compromised, immediate and sustained vigilance is paramount. The following steps are strongly advised:
- Monitor Financial Accounts: Regularly check bank accounts, credit card statements, and credit reports for any suspicious or unauthorized activity. Consider subscribing to a credit monitoring service.
- Beware of Scams: Exercise extreme caution with any unsolicited calls, emails, or SMS messages claiming to be from Revolut or other financial institutions. Phishing attempts are highly likely to follow, using the compromised data to make scams appear more credible.
- Strengthen Security: Change passwords for all online accounts, especially financial services and email. Enable two-factor authentication (2FA) wherever possible.
- Renew Identity Documents: Given that passport and driver’s license copies were leaked, individuals should seriously consider renewing these identification documents. While a new document number doesn’t invalidate the old one, it adds a layer of protection against future misuse.
- Report Suspicious Activity: Promptly report any unusual activity to Revolut, other financial institutions, and relevant law enforcement agencies.
Revolut has assured clients who did not receive notifications that their data was not affected. However, the broader implications of such a breach extend beyond direct financial loss. The psychological impact of knowing one’s deepest personal information is in illicit hands can be significant.
This incident arrives at a critical juncture for Revolut. The company recently secured a full banking license in France, is pursuing a national bank charter in the United States, and harbors ambitions for a staggering $200 billion initial public offering (IPO). While these milestones reflect its remarkable growth, such security lapses, particularly those exposing foundational identity documents, can severely impact investor confidence, regulatory approvals, and, most importantly, the trust of its vast customer base. The long-term success of any financial institution hinges not just on innovation and market expansion, but fundamentally on its ability to safeguard the sensitive information entrusted to it by its clients. Revolut now faces the challenge of demonstrating that it can not only grow but also secure its operations against increasingly sophisticated and non-technical threats.






