Revolut Data Breach Exposes Customer Identity Records via Spoofed Government Email
Passports, selfies and financial transaction histories of some customers were revealed to a fraudster using a government agency domain.

A sophisticated Revolut data breach has resulted in the unauthorized disclosure of sensitive customer identification documents and financial transaction logs. The security incident occurred after an attacker successfully utilized a deceptive communication vector masquerading as an official public authority to extract confidential compliance records.
According to a report published by Cointelegraph, the cyber intrusion compromised identity verification records such as government-issued passport images, customer identity selfies, and detailed historical transaction records. The malicious actor reportedly executed the attack by deploying a spoofed government agency domain, deceiving internal verification workflows into releasing targeted data packets.
Fintech platforms and digital banking services like Revolut handle vast repositories of Know Your Customer data to satisfy global anti-money laundering regulations. The compromise of biometric images and primary identification documents poses severe risks of secondary identity theft, targeted social engineering campaigns, and unauthorized account creation attempts across other financial ecosystems.
Cybersecurity specialists emphasize that attacks leveraging domain spoofing highlight persistent vulnerabilities at the intersection of public sector compliance requests and automated customer service infrastructures. Financial institutions face rising sophisticated phishing attempts designed to exploit regulatory communication channels that are typically given higher operational trust.
The breach exposes Revolut to potential regulatory scrutiny under strict data privacy frameworks, including the European Union's General Data Protection Regulation. Regulators routinely impose severe monetary fines and compliance remediation orders on institutions that fail to adequately verify the authenticity of third-party data requests.
Affected users are being advised to monitor their credit profiles and personal accounts for suspicious activity while practicing heightened caution against unsolicited communications. Observers will be monitoring upcoming disclosures regarding Revolut's enhanced authentication protocols and potential findings from cybersecurity audits.
Key takeaways
- Revolut customer passports, verification selfies, and transaction logs were exposed.
- The attacker gained access through a spoofed government agency email domain.
- The fintech firm faces heightened regulatory scrutiny under global privacy frameworks.
