Revolut said on Sept. 12 that it disclosed sensitive information belonging to a limited number of customers after an unauthorized party sent fraudulent records requests from a legitimate government-agency email domain. The fintech said its own systems and customer funds were not affected, but the episode exposes a different enterprise-security weakness: a request can look technically authentic and still be fraudulent.
The company told TechCrunch and The Block that it blocked the address after identifying the impersonation, contacted affected customers and alerted the relevant government agency, law enforcement, data-protection authorities and financial regulators. Revolut has not publicly identified the agency, disclosed the number of customers involved or said whether the exposure was confined to one market.
Identity and transaction records may be involved
According to notifications reviewed by the two publications, potentially disclosed information included names, dates of birth, postal and email addresses, phone numbers and copies of identity documents such as passports and driver’s licenses. Verification selfies, account statements, international bank account numbers, withdrawal records and transaction histories, including Bitcoin activity, also may have been included.
Those categories make the incident consequential even without a reported intrusion into Revolut’s core technology. Identity documents and financial histories can support targeted phishing, impersonation and other fraud long after a compromised account is secured. The company said it directly notified the customers it determined were affected.
The control failure happened in the trust layer
The reported method matters to banks, platforms and any company that routinely answers government or law-enforcement requests. Email authentication can establish that a message came through an authorized domain; it does not by itself prove that the sender was entitled to make the request or that the scope was appropriate.
Organizations handling these requests need controls that operate beyond the inbox: verified agency contacts, callback procedures, case-number validation, independent approval for sensitive disclosures and strict limits on the data returned. The same principle applies to vendors processing subpoenas, emergency requests, identity checks and customer disputes.
What remains unanswered
Revolut’s statement leaves important questions open, including how the fraudulent requests passed review, how long the activity continued and what additional safeguards have been installed. It also has not named the government domain involved, limiting the ability of other organizations to assess whether they received similar requests.
For executives, the immediate lesson is that trusted channels are not the same as trusted requests. A mature disclosure process must verify both the identity and authority of the requester before high-risk customer data leaves the organization.
