UK-based multinational online bank Revolut is reported to have inadvertently exposed customer details of high net-worth account holders following a sophisticated spear phishing attack. The incident highlights how even regulated financial institutions can be deceived by fraudulent communications that successfully impersonate legitimate government agencies.

According to a post on Telegram by independent crypto-security researcher ZachXBT: "Revolut appears to have exposed personally identifiable information (PII) for a subset of users due to failing to detect a fraudulent government request."

Revolut is reported to have received a request for information coming from what appeared to be a legitimate government agency. In fact, the request came from an unauthorised email account sent directly using the official government agency's email domain. As the communication carried valid authentication credentials, it was fulfilled under the reasonable supposition that it was an authentic request from a legitimate government agency.

High Net-Worth Customers Targeted

While the incident is likely limited in size, it is understood to have been targeted at high net-worth users. The information released on those customers is, however, extensive. It includes account holders' home addresses, emails, phone numbers, copies of passports and driver's licences together with accompanying selfie pictures, account statements, IBAN numbers, withdrawal records, and full transaction histories — including Bitcoin.

Revolut has sent out an email to the affected account holders explaining what has happened and offering support. There is, as yet, no evidence that account holders' funds have been affected. But the extent of the personal information compromised leaves no room for complacency: the exposed data leaves account holders potentially vulnerable to future fraudulent attacks. These could include identity fraud and highly targeted phishing attacks.

Calls for Stricter Verification Controls

Revolut is now facing criticism that it should have set the bar for verifying third-party data requests higher, and that a regulated financial institution handling highly sensitive data should have had sufficiently rigorous verification controls to identify even a highly sophisticated attack of this nature. The Financial Conduct Authority (FCA) and other regulators require firms to implement robust data protection measures under frameworks including UK GDPR.

However, the fact remains that financial institutions of all kinds are a primary target for cybercriminals, and that whatever safeguards are in place, threat actors will continue to employ increasingly sophisticated attack vectors to bypass them. The technique of spoofing or abusing legitimate government email domains to issue fraudulent legal process requests — sometimes called Emergency Data Requests (EDR) fraud — has been documented against major technology platforms and financial services firms alike.

This incident serves as a stark reminder that even technically valid-looking communications require out-of-band verification, particularly when they concern sensitive customer data at scale.