Drooid Logo
Back to story perspectives

Full Breakdown

Revolut Hit by Spoofed Government Email Scam, Exposing Data of Hundreds of Customers

By Drooid · · How we work

Core Event

Revolut, the London-based fintech with more than 80 million users, fell victim to a “sophisticated external impersonation scam” in which attackers used a legitimate-looking government-agency email address to request sensitive customer information. The breach resulted in the theft of identity documents, birth dates, postal and email addresses, phone numbers, verification selfies, account statements, IBANs, and full transaction histories for nearly 700 customers, according to City AM. Revolut says its core infrastructure, databases and customer accounts were not compromised, and it promptly blocked the fraudulent address and alerted relevant authorities.

How the Spoofed Request Bypassed Verification

The hackers sent a request that appeared to originate from a government body, exploiting the “emergency data request” process that obliges companies to comply when a request is legally binding. As explained by Marco Ramilli, founder of the Italian cyber-intelligence firm Yoroi (cited by Il Sole 24 Ore), the attackers possessed valid authentication credentials for a government-domain email, allowing them to masquerade as an official authority and obtain the data without triggering Revolut’s internal checks.

Official Statements & Responses

  • “We are aware of the reported incident involving Revolut and are engaging with the firm to understand the impact and the steps being taken to address any potential harm.” — Financial Conduct Authority spokesperson
  • “We can confirm we have received a report and are assessing the information provided.” — Information Commissioner’s Office

Data Summary and Ongoing Threat

The hacker group, calling itself “Revolut Smilik,” has threatened to release additional data on Telegram unless a ransom of 10,000 BTC (? $780 million) is paid, according to TechRadar and Cybernews. The leaked information includes selfies and full KYC details of at least one high-profile crypto-casino CEO. Revolut has notified the affected customers by email, describing the incident as an “external identity theft” that resulted in personal data being shared with an unauthorised third party.

Verbatim Quotes

  • “This one is deeply concerning and the implications for affected customers go well beyond a standard data breach notification,” — Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress
  • “We are aware of the reported incident involving Revolut and are engaging with the firm to understand the impact and the steps being taken to address any potential harm.” — Financial Conduct Authority spokesperson
  • “We can confirm we have received a report and are assessing the information provided.” — Information Commissioner’s Office