No firewall was breached, no server was hacked, and no password was cracked. Revolut gave the data away, because the email asking for it looked exactly like it was supposed to.
The request was real enough to pass every check that mattered
On September 12, the UK-headquartered fintech confirmed that an unauthorized third party had obtained access to sensitive customer data by submitting requests for information from an email account operating inside a legitimate government agency’s own domain infrastructure. The messages carried genuine domain authentication, the kind of technical signal, SPF, DKIM and DMARC alignment among it, that email security teams spend years training staff to trust. Revolut treated the requests as authentic government inquiries because, by every automated and procedural check available to a compliance team, they were.
What went out the door
The data disclosed included Know Your Customer documentation and detailed financial records: copies of passports and driver’s licences, identity-verification selfies, account statements, and complete transaction histories that included Bitcoin-related activity. Revolut has described the number of affected customers as limited and says the pattern of what was requested suggests the attackers were targeting high-net-worth account holders specifically, rather than harvesting data indiscriminately. The company says its systems and customer funds were not compromised, and that this was a disclosure through a legitimate-looking request channel rather than an intrusion.
The failure sits in process, not infrastructure
This is the same structural weakness behind years of emergency-data-request fraud against large technology and communications companies in the US: when a request arrives from an account inside a real agency’s domain, verifying the domain is not the same as verifying the person or the request. An attacker who gains any foothold in a government mailbox, however that foothold was obtained, inherits every ounce of trust that domain carries with every company on the other end of it. Revolut says it blocked the account, alerted the impersonated agency, law enforcement, and relevant regulators, and is applying additional protections for affected customers. Given Revolut’s footprint across the EU and UK, this is very much a GDPR and UK GDPR matter, and regulators on both sides of the Channel will be looking at how the request was validated before it was fulfilled.
What this means if your company ever receives a data request
Any organisation that handles identity documents, financial records, or other regulated personal data needs a verification path for law-enforcement and government requests that does not stop at “the email domain checks out.” That means callback verification through numbers you already hold on file, requiring requests to route through known legal or compliance liaison channels, and treating an unusual or urgent request, especially one seeking a bundle of identity and financial data on a single high-value customer, as a reason to slow down rather than speed up.
If you want a European team to review how your organisation authenticates inbound data and legal requests, harden your email authentication and verification processes, and make sure a convincing domain is never enough on its own to move sensitive customer data, contact Excello Digital. We help organisations close exactly this kind of process gap before it becomes a headline.
