Revolut handed customer data to fraudsters using government email account
British fintech company Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
The perpetrators appear to have targeted high-net-worth individuals, many of them involved in crypto asset businesses.
Revolut said over the weekend it “recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
It did not publicly identify the specific government domain used. Alleged extortion images circulated on Telegram by an account claiming to have perpetrated the attack suggests the email originated from an Italian domain.
A range of Italian authorities contacted by Recorded Future News did not respond to requests for comment. The Telegram account has since been suspended and not all of the details contained in its posts could be confirmed.
One of Revolut’s customers, whose purportedly stolen data was shared as proof of the breach in the Telegram posting, did not dispute the authenticity of the information in a post on social media.
Revolut said only a limited number of customers were affected and that it had notified them directly.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” the company said.
It is not known whether the same compromised domain targeted other financial organisations. The perpetrators said they were calling for Revolut to make an extortion payment in order to avoid customer data being released.
Revolut declined to comment on the existence of any extortion attempt when contacted by Recorded Future News.
Marc Zeller, a cryptocurrency entrepreneur, wrote on X that he had woken up on Saturday to find “all my data leaked by Revolut.”
“The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or ‘we will close your account in 20 days’,” wrote Zeller. “Now we know they been fooled by hackers and did all the work for them like good little lap dogs.”
Other impacted individuals shared customer notices explaining the exposed data includes birth dates, postal and email addresses, phone numbers, passport and driver’s license copies, verification selfies, bank statements, international bank account numbers (IBAN), withdrawal records and transaction histories, including Bitcoin activity.
Mark Karpelès, the former CEO of the Mt. Gox bitcoin exchange, was among those saying they were impacted.
In a series of similar breaches in 2021 and 2022, hackers linked to the Lapsus$ group used compromised law enforcement accounts and forged emergency data requests to obtain user information from technology companies including Apple, Meta and Discord.
The FBI has previously issued an alert about fraudulent emergency data requests, noting an “increase in postings on criminal forums” offering access to compromised email accounts to send such requests.
Revolut says it has more than 80 million customers globally and is considering a public listing that could value it at up to $200 billion.
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79



