Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories
Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories
Read Time:3 Minute, 21 Second

Revolut has disclosed a security incident in which sensitive customer information was released in response to a fraudulent request that appeared to come from a legitimate government agency. The company says its banking systems, mobile application and customer accounts were not penetrated. Instead, the attackers reportedly abused an unauthorized mailbox operating under an official agency domain to make the request appear genuine.

Only a limited number of customers were said to be affected, but the exposed records were unusually sensitive. They reportedly included identity documents, verification selfies, contact details, account information and complete transaction histories. That combination could give criminals the context needed to build highly convincing fraud or impersonation attempts.

An authentic domain carried an illegitimate request

Email authentication helps a recipient determine whether a message was authorized by the domain it claims to use. It does not prove that the person controlling the mailbox is acting legitimately. In this case, the official domain and its valid authentication signals apparently increased the credibility of a request that should not have been honored.

Revolut characterized the operation as sophisticated social engineering rather than a compromise of its core infrastructure. After identifying the problem, the company said it blocked the unauthorized source, informed relevant authorities and contacted affected users. It also stated that customer funds remained safe.

The distinction matters for technical scoping, but it does not reduce the sensitivity of the data disclosure. Security controls around legal, law-enforcement and regulatory requests are part of the overall system that protects customer information. Attackers only need to defeat the weakest trusted process, whether that process is software, a mailbox or a human approval workflow.

Identity documents and financial history create lasting risk

The disclosed information reportedly included names, birth dates, occupations, postal and email addresses, phone numbers, passport or driving-licence copies and facial-verification images. Revolut said biometric facial telemetry was not involved, but document scans and onboarding selfies can still support identity theft and account-recovery fraud.

Financial records reportedly included IBANs, account status, opening dates, wallet references, withdrawal details and transaction histories, including Bitcoin-related activity. Unlike a password, much of this information cannot simply be changed. Detailed transaction data may also reveal relationships, spending patterns or an individual’s apparent wealth.

Cryptocurrency users could face particular danger. An attacker who knows that a target has significant digital-asset activity can tailor a lure around a real transaction, pose as compliance staff, attempt a SIM swap or apply pressure through extortion. Public commentary about the incident has raised the possibility that wealthy users were deliberately selected, though affected customers should act cautiously regardless of their account balance.

What affected customers should watch for

  • Treat unexpected calls or messages claiming to come from Revolut, police, tax agencies or cryptocurrency exchanges as potentially hostile.
  • Verify requests through contact details obtained independently from the official app or website.
  • Review account activity and enable the strongest available protections on email, mobile and financial accounts.
  • Be suspicious when a caller cites accurate personal or transaction details; leaked facts do not make the caller trustworthy.

Customers should also consider the local options available for identity-document monitoring or replacement. Any protective action should be based on Revolut’s direct notification and guidance from the relevant issuing authority, not instructions arriving through an unsolicited message.

High-risk disclosures need out-of-band verification

Organizations holding KYC, medical, telecom or financial records should require more than a credible-looking email before releasing them. A robust workflow can include a second reviewer, validation through a known agency contact, case-number checks, narrowly scoped exports and immutable records of each approval. Requests involving identity documents or full financial histories deserve the strongest controls.

This incident is a warning about treating technical authenticity as equivalent to institutional authority. Domain checks remain useful against ordinary spoofing, but a compromised or misused legitimate account can pass them. Independent verification is the control that breaks that chain of trust before an attacker turns a borrowed identity into a damaging disclosure.

Source: Cyber Security News.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories, use the discussion on Forum.

>> forum community

Comments

Leave a Reply