Revolut Says It Was Tricked Into Sharing Customer Data in Government Impersonation Scam
Revolut says spoofed government email led it to share sensitive customer data; attackers demand 10,000 BTC ransom.
Revolut told TechCrunch that the threat actor "utilized a legitimate government agency domain email to submit fraudulent requests for information." TechRadar reported that the attackers either broke into or spoofed an email address belonging to police, tax authorities or another government body with statutory powers to demand information, then used it to ask Revolut to hand over customer data.
Cybernews reported that the compromised data includes customers' birth dates, postal and email addresses, occupation, phone numbers and copies of identity documents. TechCrunch added that verification selfies, account statements and transaction histories may also have been compromised, together with IBANs, withdrawal records, complete transaction histories and Bitcoin transactions. TechRadar said that if these reports are confirmed, the incident will be a fiasco for Revolut.
Revolut has not disclosed exactly how many people are affected. The company said the number was "very limited" and that all affected customers had already been notified. A company spokesperson told Reuters over the weekend: "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators."
According to Coin Bureau, the criminals have started leaking sensitive data on Telegram in an effort to pressure Revolut into paying the ransom. The publication shared screenshots of the threat actors apparently leaking a selfie and "full KYC" of a CEO of a crypto casino website, and said the crooks are demanding 10,000 BTC in exchange for deleting the data. TechRadar reported that this would put the ransom demand at approximately $780 million.
Muhammad Yahya Patel, vCISO and Cybersecurity Advisor at Huntress, said the incident is deeply concerning and that its implications for affected customers go well beyond a standard data breach notification. "Passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, addresses that's not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests," Patel said. He added that every component needed to impersonate someone, open accounts in their name or bypass checks at other financial institutions is in that package. On the dark web, he said, that kind of profile does not sell as individual records but as a ready-made fraud pack, and it commands a significant premium because of its completeness.
"For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high," Patel said. "The question isn't why an attacker tried this. It's why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it."