Revolut may have handed sensitive customer information to fraudsters after accepting a forged request that appeared to come from a government body, according to Reuters.
The criminals used an email address with a government domain to send the fabricated requests to the financial company. The information potentially exposed included customers’ addresses, telephone numbers, copies of identity documents, verification selfies, bank statements and transaction histories.
A forged official request
The reported deception relied on the appearance of official authority. By using an address connected to a government domain, the fraudsters presented their requests as though they had been issued by a legitimate public institution. That appearance was enough for Revolut to believe the requests were genuine, Reuters reported.
The materials do not identify the government body whose identity was allegedly imitated, nor do they give the number of customers whose information may have been disclosed. They also do not establish that every category of data listed was handed over in every case. The reported risk is that such information could have been released in response to the fraudulent requests.
The distinction is important. The incident described by Reuters concerns a potential disclosure of confidential customer records, rather than a confirmed account of every piece of information accessed by the criminals. But the range of data cited means the alleged requests reached far beyond a single contact detail.
Why the data is particularly sensitive
Addresses and telephone numbers can reveal how to contact or locate a customer. Copies of identity documents contain information used to establish who a person is, while verification selfies are collected to help confirm that a customer matches those documents. Bank statements and transaction histories can expose details of a person’s financial activity.
Taken together, the categories described in the report represent a detailed picture of a customer’s identity, contact information and banking records. That is why the alleged success of a forged official request matters even though the material does not provide a confirmed total of affected customers or a complete account of what the fraudsters did with the data.
The episode also highlights the central weakness exploited by the deception: the apparent authenticity of the request. The address used by the criminals was designed to make the communication look official, while the request itself was treated as legitimate by the recipient. The reported disclosure therefore depended not only on the existence of a forged message, but on the trust attached to its apparent source.
Unanswered questions about the disclosure
The available account leaves key details unresolved. It does not say when the requests were sent, how many were accepted, how many customers may have been affected or whether all the listed types of information were included in the material obtained by the fraudsters.
It also does not identify the specific checks used by Revolut before the information was released. That missing detail makes it impossible, on the evidence available, to determine how widely the method worked or whether the company regarded the requests as part of a wider pattern of fraudulent communications.
What is clear from the report is that a government-style email address was enough to give the criminals’ requests credibility. The potential exposure of identity documents, selfies, statements and transaction histories makes the incident more serious than an ordinary mistaken reply, while the absence of confirmed figures leaves the scale of the disclosure uncertain.
Should companies treat requests for sensitive customer data from government-linked email domains as legitimate only after an independent verification step?