Revolut Discloses Customer IDs and Financial Data to Impersonated Government Email
What Happened – Revolut confirmed that it supplied personal identification documents, selfies, and account statements for a limited set of customers to an unauthorized party after responding to a fraudulent request that appeared to originate from a legitimate government‑agency email domain. The incident was a social‑engineering impersonation, not a technical intrusion, and no customer funds were directly taken.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of inadequate verification of external data‑request channels – a control‑area that continuous monitoring and auditable evidence can mitigate.
- Highlights the need for documented security‑awareness training and incident‑response playbooks that capture social‑engineering attempts as part of a defensible audit trail.
- Aligns with the control objective of “Verified third‑party data requests and secure handling of personal information,” which maps to multiple frameworks (e.g., NIST CSF 2.0).
Who Is Affected – Global digital‑banking platforms, fintech providers, and any organization that processes personal identification data on behalf of customers.
Recommended Actions
- Review and harden verification procedures for any external request that involves personal or financial data.
- Institute regular security‑awareness training that includes realistic impersonation scenarios.
- Ensure all data‑request activities are logged, reviewed, and retained as audit evidence.
- Conduct a control‑gap assessment against the “verified third‑party request” objective and remediate any deficiencies.
Source: Malwarebytes Labs
Technical Notes – The attack leveraged a spoofed email address on a legitimate government domain to bypass Revolut’s request‑validation process. No malware, CVE, or system exploit was involved; the breach vector was purely social engineering. Exposed data included dates of birth, addresses, passport and driver’s‑license scans, verification selfies, and transaction histories. Source: Malwarebytes Labs