British financial technology company Revolut has confirmed that sensitive customer information was disclosed after fraudsters used an unauthorized email account within a legitimate government agency domain to submit fraudulent requests for customer information.
The incident represents a particularly serious form of social engineering because the attackers did not rely solely on a counterfeit website, forged email address, or obvious phishing message. They reportedly operated through an authentic government domain, giving fraudulent requests the appearance of legitimate communications from a public authority.
Revolut said it recently identified what it described as a sophisticated external impersonation scheme in which an unauthorized third party used a legitimate government agency domain email address to request customer information.
The company has not publicly identified the government agency or domain involved.
Blockchain investigator ZachXBT said the incident appeared to target higher-net-worth users, including individuals connected to cryptocurrency, though Revolut has not confirmed that customers were deliberately selected on that basis.
Revolut initially described the number of affected customers as limited. Newer reporting indicates that 680 customers were notified about the incident.
The company said it blocked the email address after discovering the activity and alerted the government agency involved along with law enforcement agencies, data protection authorities, and financial regulators.
The incident demonstrates a weakness that extends beyond conventional account compromise. Government information request systems allow law enforcement and public agencies to seek customer information from private companies through established legal and investigative processes.
That trust relationship can become an attack surface when criminals obtain access to an unauthorized email account operating within legitimate government infrastructure.
A request originating from an authentic agency domain carries significantly greater credibility than one sent from an unknown or newly registered address. If authentication procedures rely heavily on the apparent legitimacy of the sender, a compromised government account can give an attacker access to information that ordinary phishing operations could never obtain.
The customer information reportedly exposed in the Revolut incident was extensive.
Affected customers have described notices identifying exposed information that included dates of birth, postal addresses, email addresses, telephone numbers, passport copies, driver’s license copies, identity-verification photographs, bank statements, international bank account numbers, withdrawal records, transaction histories, and records involving Bitcoin transactions.
That combination of information creates several possible risks.
Identity documents can support impersonation and fraudulent account creation. Contact information can be used in targeted phishing operations. Banking records can provide criminals with detailed knowledge of a victim’s finances. Transaction histories can reveal financial relationships, account behavior, cryptocurrency holdings, or patterns attackers could exploit during subsequent social-engineering attempts.
Verification selfies present another problem because financial institutions frequently use facial images as part of identity-verification procedures.
A criminal possessing a victim’s passport, driver’s license, identifying information, financial records, and verification photographs has a much more complete identity package than could normally be obtained through a simple database leak.
Marc Zeller, a cryptocurrency entrepreneur, publicly stated that his information was exposed during the incident.
Mark Karpelès, the former CEO of the Mt. Gox bitcoin exchange, also said he was among the affected customers.
The apparent concentration on individuals connected to cryptocurrency raises additional security concerns because criminals targeting digital-asset holders can use stolen personal information to construct highly tailored attacks.
Knowledge of cryptocurrency transactions can help attackers identify potential holdings, exchanges used by a target, financial counterparties, and transaction patterns.
That information can then become the foundation for additional phishing, impersonation, account-recovery fraud, SIM-swapping attempts, extortion, or attacks designed to obtain access to digital wallets and financial accounts.
The attackers reportedly threatened to release the stolen customer information unless Revolut paid a ransom.
Revolut has not publicly confirmed the details of any extortion demand.
It also remains unclear whether the compromised government email infrastructure was used to submit fraudulent requests to other financial institutions or technology companies.
That question is important because access to a legitimate government account could potentially be reused against numerous organizations before the compromise is discovered and blocked.
Fraudulent government information requests are not a new technique.
Similar incidents have previously involved criminals gaining control of government or law enforcement email accounts and using those accounts to impersonate investigators requesting information from private companies.
The method can bypass many of the warning signs associated with traditional phishing because the fraudulent request can originate from infrastructure belonging to a real government organization.
The FBI has previously warned that compromised government email accounts can be sold or advertised in criminal communities for use in submitting fraudulent government information requests.
Such access gives criminals an opportunity to abuse processes originally created for urgent public-safety investigations.
The Revolut incident demonstrates why the authenticity of an email domain cannot be treated as sufficient proof that a government information request is legitimate.
A message can originate from a legitimate government domain while still being controlled by an unauthorized individual.
Organizations handling sensitive customer information therefore face the difficult task of validating not only where a request originated, but also whether the person sending it is actually authorized to make the request.
Additional verification can include independent confirmation of the requesting officer or agency, verification through established agency contact channels, examination of case information, validation of request identifiers, and stronger authentication procedures for sensitive government information requests.
Those protections become particularly important when a request seeks highly sensitive information such as identity documents, banking records, transaction histories, or financial account information.
The incident also raises questions about how much customer information should be released in response to a single government information request and whether different categories of information should require additional verification.
A request for basic subscriber information carries a different risk profile from a request involving passport copies, banking documents, identification photographs, and transaction histories.
Separating those categories and applying stronger verification requirements to highly sensitive information could reduce the consequences of a compromised government account.
Revolut has grown into one of the largest financial technology platforms in the world, reporting more than 80 million customers globally.
The company is also considering a potential public listing that could place its valuation as high as $200 billion.
That scale makes identity verification, law enforcement requests, financial records, and customer-data security critical parts of its infrastructure.
The incident was not described as a conventional intrusion into Revolut’s internal systems. The more troubling issue is that attackers appear to have manipulated a legitimate information-sharing process by presenting fraudulent requests through trusted government infrastructure.
That distinction matters.
The attackers did not necessarily need to defeat Revolut’s network defenses if they could convince the company to provide the information voluntarily through a process designed for legitimate authorities.
It is a reminder that cybersecurity does not end at firewalls, encryption, multifactor authentication, or endpoint protection.
Trust itself can become the vulnerability.
When a criminal controls a trusted identity, whether that identity belongs to a government agency, business, executive, employee, or financial institution, security systems built around that trust can be turned against the organizations they were designed to protect.
For the customers affected by the Revolut incident, the potential consequences may extend well beyond the original disclosure.
Passwords can be changed and compromised payment cards can be replaced. Passports, identification documents, financial histories, addresses, dates of birth, and biometric verification images cannot be replaced nearly as easily.
That makes the long-term protection of affected customers just as important as identifying how the fraudulent government information requests succeeded in the first place.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



