THE BRIEFWhat happened
Help Net Security reports that someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. Revolut reportedly confirmed the incident on September 12 and told the publication that a limited number of customers were affected.
According to the notification described in the report, data may have included birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences. The supplied account does not explain how the impersonation succeeded, whether the attacker accessed other systems, or whether the affected records were misused.
Revolut reportedly contacted affected customers directly, so recipients should verify any message through the bank’s official application or a trusted support route rather than following links in an email. The incident shows how authority-based impersonation can turn a communication channel or support process into a route to sensitive financial records.
Organizations should review requests that rely on official-looking domains, urgent instructions, or claimed government authority, especially when they seek customer data.