Revolut “hands over” the data of hundreds of customers after a scam via certified email: what ended up in the hands of criminals

It was not necessary to break into Revolut’s cyber defenses to obtain its customers’ confidential data. It was enough to convince the company that it was a public authority requesting them. A scam using an …

Revolut "hands over" the data of hundreds of customers after a scam via certified email: what ended up in the hands of criminals

It was not necessary to break into Revolut’s cyber defenses to obtain its customers’ confidential data. It was enough to convince the company that it was a public authority requesting them. A scam using an email address actually belonging to a government agency caused the fintech to hand over identification documents, contact details and financial information to a person who had no right to receive them. According to what was leaked, the scammers would have used an Italian certified email to carry out the scam.

How criminals deceived Revolut

Revolut confirmed the incident, stating that its IT systems were not hacked and that the money deposited into the accounts was not stolen. The problem, however, concerns the confidentiality of the information stored by the company: data which, once released, can be used for much more credible scams than a common phishing attempt.

The reconstruction provided by the company speaks of a “sophisticated impersonation scam”. An unauthorized person would send requests for information through the authentic domain of a government agency, making the communication appear to come from an authority entitled to obtain the data. It is not an unusual scam: already in 2021 a group of very young hackers had used real email boxes of carabinieri and police officers to have data delivered by big tech companies such as Meta, Microsoft, Wind or Vodafone, just to name a few.

Revolut considered the requests legitimate and provided the information. Only later did it realize the deception, block the address used and alert the government agency involved, law enforcement agencies, data protection authorities and financial regulators.

According to the Financial Times, the people affected would be 680. Revolut has not publicly confirmed this figure, limiting itself to speaking of a small number of customers contacted directly. It was not even clarified in which countries the users involved live.

The case therefore presents different characteristics compared to a traditional cyber attack. The criminals would not have entered the company’s databases and would not have directly stolen the information: they would instead have exploited the procedures through which banks and financial platforms respond to requests from the authorities.

From passports to transaction history

However, the amount of data potentially delivered makes the incident particularly delicate. In communications sent to users, viewed by TechCrunch, Revolut lists names, dates of birth, home addresses, telephone numbers, email addresses and copies of passports or driving licences.

Depending on the customer, the files may also include photographs used to verify identity, account statements and transaction histories, including cryptocurrency transactions. Passwords and access codes, however, would not be compromised.

Mark Karpelès’ post on X

Among those involved is Mark Karpelès, former CEO of the cryptocurrency platform “Mt. Gox”. It was Karpelès himself who reported that the material would have been sent through the Italian certified email system and that one of the messages would have had a size close to 60 megabytes. The detail of the certified e-mail, however, was not officially confirmed by Revolut, which did not indicate either the entity impersonated or the country from which the requests originated.

The criminals claiming possession of the data also allegedly threatened to publish it if the company did not pay a ransom. In the United Kingdom, the Information Commissioner’s Office, the competent authority for personal data protection, opened an investigation after receiving Revolut’s report.

The danger now is “tailor-made” scams

The fact that the accounts have not been compromised does not eliminate the risks for customers. A copy of your passport cannot be replaced as easily as a password. If address, telephone, IBAN and financial movements are added to the documents, scammers can construct extremely convincing communications.

The victim could, for example, receive a phone call from someone who presents himself as an employee of the Revolut anti-fraud service and who knows actual transactions carried out, personal data and even the type of document used to open the account. After gaining the trust of the interlocutor, the fake operator could claim that the account is under attack and ask to transfer the money to a “safe” account. That account, of course, would be controlled by criminals.

Revolut and other banks do not ask customers to secure their savings through a bank transfer arranged over a phone call. Whoever received the communication regarding the data leak should therefore be wary of unexpected calls, emails and messages, interrupt contact and contact assistance independently through the official app. It is also advisable to monitor account movements with particular attention and immediately report any transactions or credit requests that were never authorized.

Ultimately, the incident shows a weakness that goes beyond Revolut. The authenticity of the sender address alone does not guarantee that a request is legitimate: an institutional account can be compromised or misused. When passports, bank statements and entire financial histories are at stake, independent verification of the identity of the person requesting the data is needed. In this case, that control didn’t prevent highly sensitive information from falling into the wrong hands.