BNB $730.32 +1.24%
XRP $1.49 +9.48%
ETH $2,593.18 +3.42%
BTC $79,414.84 +2.75%
BNB $730.32 +1.24%
XRP $1.49 +9.48%
ETH $2,593.18 +3.42%
BTC $79,414.84 +2.75%
BREAKING
Finance News

Revolut Duped by Impersonation Scam, Exposing Customer KYC Data to Fraudsters

Revolut Hit by Impersonation Scam That Exposed KYC Records via Fake Government Email
Revolut Hit by Impersonation Scam That Exposed KYC Records via Fake Government Email

Community Trust ScoreVerified

83%
Real
Verified40 votes
Updated 2 hours ago

Revolut got played. A sophisticated impersonation scam tricked the fintech giant into handing over customer data after fraudsters sent requests from an email address sitting inside a legitimate government agency domain. The company didn’t catch it in time.

The breach came to light through on-chain investigator ZachXBT, not through any internal disclosure from Revolut itself. Once the company figured out what had happened, it blocked the fraudulent email address and said it notified relevant authorities and regulators. A Revolut spokesperson was pretty clear that no systems were compromised and no client funds were touched. But that’s kind of where the clarity ends. Revolut hasn’t said which government agency’s domain got misused. It hasn’t said how many customers had their data exposed. And it hasn’t said whether it changed anything about how it verifies incoming government data requests going forward. Those are big gaps.

No systems breached. But customer data went somewhere it shouldn’t have.

Advertisement

Why KYC Data Is Such a Tempting Target

Financial institutions collect a lot. Revolut, like every regulated fintech operating across multiple jurisdictions, pulls in identification documents, transaction records, and personal details to satisfy anti-money laundering rules. That data doesn’t disappear after onboarding — it gets retained for years, sometimes a decade or more depending on the jurisdiction. That’s the regulatory reality. And it’s also what makes these databases so valuable to criminals.

Revolut’s public-facing privacy policies say the company uses secure storage and limits employee access. That’s the standard line. But the policies don’t get into specifics about how the company actually authenticates government requests before responding to them. There’s no mention of multi-step verification, no detail on whether a second channel is used to confirm that a request is real. That gap probably matters a lot here, because the whole scam hinged on Revolut treating a spoofed email address as legitimate.

Scammers with access to KYC records can do real damage. Identity documents open the door to impersonation. Transaction histories make phishing attacks sharper and more convincing — a fraudster who knows what you bought, when, and where can craft a message that doesn’t look like a scam at all. These records are basically a toolkit for targeted fraud.

Extortion Allegations and What Remains Unclear

There are also allegations floating around about ransom demands and the possible publication of customer files. Revolut hasn’t confirmed any of that. It’s unclear whether those claims have any basis, and the company seems to be staying quiet on the details. Maybe there’s an active investigation. Maybe there’s nothing to confirm. No details on that front.

What’s worth noting separately: there was a prior incident involving a former Revolut employee. Revolut itself said there’s no confirmed link between that case and this breach. That’s probably the right call to flag, but it also means two separate data-related incidents have now touched the company within a relatively short window. Whether that’s coincidence or a pattern, it’s the kind of thing regulators tend to notice.

Social engineering is genuinely hard to defend against when the attack uses a real domain. That’s the uncomfortable truth here. A fraudster who gets access to — or can spoof — an email address within a government agency’s actual domain has a significant advantage. Most verification workflows are built around trusting known domains. If the domain looks right, a lot of systems and a lot of people will go along with the request. Revolut isn’t the first institution to fall for something like this, and it won’t be the last.

But the fallout can be serious. Regulatory scrutiny tends to follow breaches like this, especially when the institution can’t explain clearly what went wrong or what it’s doing differently. Customer trust erodes fast when people feel like their identity documents are floating around somewhere they shouldn’t be. And the reputational hit compounds when a company stays vague about the scope.

Revolut’s user base is massive. The company operates across dozens of countries and has tens of millions of customers. Even a small percentage of accounts affected translates into a large absolute number of people who may now be at elevated risk of identity fraud or targeted phishing.

The company says it’s secure. It says funds are safe. But the verification question — how exactly does Revolut confirm that a data request is legitimate before it responds — still doesn’t have a public answer.

Frequently Asked Questions

What type of data was exposed in the Revolut scam?

Fraudsters obtained customer data by sending requests from an email address within a legitimate government agency domain, though Revolut hasn’t specified exactly which data fields were disclosed or how many customers were affected.

Did the Revolut scam affect customer funds or internal systems?

According to a Revolut spokesperson, the scam did not affect the company’s systems or client funds — only customer data was exposed through the fraudulent requests.

Why It Matters

This incident underscores the vulnerabilities that fintech companies face in the increasingly complex landscape of cybersecurity, particularly regarding Know Your Customer (KYC) processes. As digital finance continues to grow, the potential for data breaches linked to social engineering tactics poses significant risks not only to customer trust but also to regulatory scrutiny. Such events may compel regulators to enforce stricter compliance measures, impacting how fintech firms manage their data security protocols moving forward.

Community Trust IndexHigh Confidence
83%
Real
Real83%18%Fake
40 community signals

James Thorp

James Thorp is a passionate crypto journalist from South Africa specializing in Litecoin, Dash, and emerging digital assets. With years of experience covering the crypto markets, James delivers in-depth analysis and breaking news on altcoins, blockchain adoption, and decentralized payment networks for The Currency Analytics.

Advertisement

Related Stories