A recently disclosed Revolut data breach has highlighted the expanding threat of attackers exploiting legal compliance mechanisms to extract sensitive customer data. The London-based fintech giant, which serves over 80 million retail users and 800,000 business customers across 160 countries and regions, confirmed that an unauthorized third party successfully duped its compliance team into handing over extensive personally identifiable information (PII) and detailed transaction histories.
The incident occurred when an attacker submitted formal information requests using a valid email account on a legitimate government agency domain. Because the incoming messages carried valid technical domain authentication credentials, Revolut fulfilled the requests under the reasonable belief that it was responding to an authentic law enforcement inquiry.
Fraudulent Compliance Requests and Technical Authentication
Financial institutions worldwide are legally obligated to respond to lawful requests for customer information submitted by regulatory bodies, intelligence services, and law enforcement agencies. Attackers increasingly exploit this requirement by taking control of official government email accounts or leveraging improperly configured domain infrastructure to impersonate legitimate authorities.
In this case, the attacker sent requests originating from an authentic government domain. Standard email authentication protocols—such as SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance)—passed technical verification checks because the domain itself was authentic. To the automated filters and human compliance handlers receiving the request, the communication appeared indistinguishable from a legitimate agency inquiry.
Revolut discovered the breach after fulfilling the requests, at which point the company immediately blocked the attacker’s email address, notified the impersonated government agency, and reported the incident to relevant law enforcement, data protection, and financial regulatory authorities. Revolut confirmed that its internal IT systems and customer funds were not compromised or affected.
Scope of the Exposed Information
While Revolut stated that only a limited subset of its user base was affected, the breadth of data handed over to the threat actor is severe. The compromised data encompasses complete identity profiles, regulatory verification assets, and detailed financial histories:
- Identity & KYC Documentation: Full names, dates of birth, occupations, residential addresses, email addresses, and telephone numbers, alongside high-resolution copies of driver’s licenses and passports.
- Biometric Verification Assets: Facial verification images and selfies submitted during Know Your Customer (KYC) onboarding processes.
- Financial & Transaction Records: International Bank Account Numbers (IBANs), detailed account statements, historical withdrawal records, and complete transaction logs, including cryptocurrency (Bitcoin) transaction details.
The exposure of raw identity documents alongside biometric verification selfies creates significant downstream risk for affected customers. Threat actors possessing both government IDs and matching KYC selfies can easily attempt to bypass identity verification controls at other financial institutions, cryptocurrency exchanges, and online services.
High-Value Targeting and Abuse of Legal Data Requests
This incident fits into a broader operational pattern observed across the threat landscape involving the abuse of Emergency Data Requests (EDRs) and legal demands. Over recent years, threat actors have actively targeted municipal, state, and national government email systems—often acquiring valid credentials through infostealer logs, credential stuffing, or targeted phishing—specifically to weaponize those accounts against financial firms and tech platforms.
Observations from crypto fraud investigator ZachXBT indicate that while the breach impacted a relatively small number of accounts, the compromise appears to have selectively targeted high-net-worth users. The inclusion of Bitcoin transaction histories and full account statements suggests the attacker was seeking detailed financial intelligence on specific targets rather than conducting a wide-scale, opportunistic data harvest.
This is not Revolut’s first experience with data security incidents. In September 2022, the fintech provider suffered a cyberattack that exposed the personal, contact, and financial records of 50,150 customers. However, unlike traditional network intrusions, this latest incident relied on social engineering directed at human compliance workflows backed by compromised trust anchors.
Strengthening Legal & Compliance Verification Controls
Preventing malicious compliance requests requires organizations to overhaul how legal demands are vetted, moving beyond reliance on inbound email domain authentication alone:
- Mandatory Out-of-Band Verification: Compliance procedures must require independent, secondary verification for legal requests before sensitive data is dispatched. High-risk requests—particularly those involving identity documents or full transaction histories—should require phone verification through official, independently verified law enforcement registry numbers rather than relying solely on email communications.
- Portal-Based Fulfillment Systems: Organizations should deprecate the transmission of unencrypted customer PII via email. Law enforcement inquiries should be funneled exclusively through secure, authenticated web portals requiring multi-factor authentication and identity verification for requesting officers.
- Strict Anomaly Detection on Compliance Queues: Compliance teams should implement monitoring controls for unusual request patterns, such as an unfamiliar government domain requesting data on high-net-worth accounts, uncharacteristically broad data scopes, or requests originating from jurisdictions unrelated to the customer’s residency.
- Targeted Support for Impacted Users: Affected customers should immediately monitor their accounts for secondary targeted phishing attacks, register fraud alerts on their exposed identities, and update authentication credentials across all linked financial accounts.
Related content
Accenture Confirms Data Breach After Source Code and Credentials Stolen
Security NewsAccenture Faces Data Breach: 35GB of Source Code Allegedly Stolen
Security NewsAesto Discloses AWS Cloud Breach Exposing 9.5 Million Patient Records
Security NewsAesto Health Data Breach Exposes 9.5 Million Patient Records
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call