Revolut Employees Fall Victim to Impersonation Scam Leading to Data Breach of Nearly 700 Customers
The Financial Times reports that digital bank Revolut handed over sensitive data of nearly 700 customers to cybercriminals impersonating government officials in a social engineering attack, involving passport information, bank account details, and home addresses.
According to insiders, Revolut has contacted 680 customers it believes were affected, informing them of the data breach. The incident was triggered when attackers obtained a real email account from a government agency and sent what appeared to be a legitimate official data request to Revolut from that email.
After verifying that the request came from a government domain, Revolut complied, providing not just basic identity information but also customer addresses, verification photos used for identity checks, scans of identification documents, and records of some customers' Bitcoin transactions—meaning the attackers also gained access to victims' cryptocurrency holdings and trading activities.
After obtaining the data, the attackers turned to extortion: threatening to publicly disclose all the data unless Revolut or the affected customers paid a ransom, escalating the incident from a simple data breach to an extortion case.
The UK's Information Commissioner's Office (ICO) has confirmed its involvement in investigating the matter, meaning the incident has entered the formal review process of UK data protection regulation, and Revolut will face regulatory inquiries rather than relying solely on internal crisis management. Among the affected customers is Mark Karpelès, former CEO of Mt Gox—who previously experienced the largest Bitcoin exchange theft in history—now appearing on another list of victims in a cryptocurrency data breach.
Mechanically, this incident does not involve traditional buyers and sellers but has clear pressure and damage parties: the attackers are the demanders, monetizing the stolen data through extortion threats, while customers' passport, address, and Bitcoin activity information, if disclosed or sold, could be directly used for identity theft or targeted scams; Revolut is the pressured party, needing to respond to the ICO's formal investigation (which may lead to penalties) while reassuring the 680 customers directly notified. Revolut's public statement—that the system and customer funds "were not affected" and refusing to confirm the number of affected individuals—frames the incident as a "human process flaw" rather than a "systemic security failure," aiming to mitigate the impact on its banking license and valuation narrative.
Source: Public Information
ABAB AI Insight
This is not the first time Revolut has been involved in a data security incident: in 2022, Revolut suffered a cyber attack that exposed personal information of over 50,000 customers, highlighting issues with internal security processes not keeping pace with user growth during rapid expansion. The attack path in this incident did not involve breaching systems but rather obtaining a real government email and directly requesting cooperation from employees, indicating that issues remain focused on human and process review stages rather than purely technical defenses.
Revolut's resource investment focus in recent years has been on license expansion and product line growth—applying for and obtaining a UK banking license, advancing market access in multiple countries, and expanding cryptocurrency trading and multi-currency account services—whether the pace of building security and compliance teams matched this expansion rhythm is the real issue pointed out by this incident: an institution that sells its "bank" identity as the core growth story has its identity verification process bypassed by an email, shaking the credibility foundation of that story.
Similar tactics of "disguising official identity to deceive internal personnel into cooperation" have appeared in previous attacks on companies like Uber and Okta by the LAPSUS$ hacker group, and are of the same nature as the social engineering attack on MGM Resorts in 2023, where attackers impersonated employees to bypass identity verification for system access—common insight among attackers is that companies' trust in requests that "look official/internal" is often more fragile than technical firewalls, and verification costs are easily sacrificed for "efficiency" considerations.
This incident essentially belongs to a structural adjustment driven by regulatory changes: the ICO's formal involvement means that regulators are beginning to treat "actively handing over data due to social engineering deception" and "direct system breaches" equally, both considered failures to fulfill data protection obligations, rather than shifting responsibility to "external hackers being clever." This mechanism will require fintech companies to establish higher-intensity secondary verification processes for identity verification requests when handling sensitive KYC documents like passports and IDs, expanding compliance costs from "preventing external intrusions" to "preventing internal misjudgments," as the boundaries of regulatory accountability extend from system security to process security.
ABAB News · Cognitive Laws
- A real email is more useful than a real attack.
- Efficiency kills verification, verification kills trust.
- Regulation does not distinguish whose fault it is, only recognizes who failed to protect.