Revolut Handed Customer Data to Fraudsters Posing as Government Officials
Revolut, the British fintech app with over 80 million customers worldwide, confirmed it handed sensitive customer data to fraudsters after being fooled by a fake emergency data request sent from a real government email account, according to The Record.
The attackers appear to have compromised a legitimate government domain — likely Italian, based on posts that circulated briefly on Telegram — and used it to submit what looked like an authorised request for user information. Because the email came from a trusted address, Revolut complied.
The exposed data is extensive: birth dates, home and email addresses, phone numbers, passport and driving licence copies, verification selfies, bank statements, IBAN numbers, and full transaction histories including Bitcoin activity.
The targets were not random. The attackers focused on high-net-worth individuals with ties to crypto businesses. Cryptocurrency entrepreneur Marc Zeller and Mark Karpelès, former CEO of the Mt. Gox bitcoin exchange, were among those publicly confirming their data was taken.
The attackers subsequently demanded an extortion payment, threatening to release the stolen data if Revolut refused. Revolut declined to confirm or deny whether any payment was made.
This technique — using compromised law enforcement or government accounts to extract user data under false pretences — is not new. The Lapsus$ group used the same playbook against Apple, Meta and Discord in 2021 and 2022.
What you should do: If you use Revolut, monitor your account for unusual activity and be alert to phishing attempts using your personal details. Consider placing a fraud alert with your bank if you hold significant assets through the platform.
Sources

