The fintech platform Revolut faced a security incident showing that cybercriminals can deceive not only ordinary users but also large corporations. Instead of a usual server hack or password theft, the attackers used psychological and technical manipulation. They sent requests on behalf of a government agency (state authority) that passed all system authenticity checks.
How the scheme worked and what the attackers obtained
The incident happened because the fraudsters managed to use a real electronic domain of a government body (state authority). Since the messages had valid cryptographic signatures and domain authentication, the internal support and security service of the fintech giant perceived it as an official request from law enforcement or regulators.
Believing in the authenticity of the documents, employees handed over a full package of confidential information about a limited number of users to the attackers. TechCrunch noted that among the disclosed data were:
Personal and contact data: full names, birth dates, current professions, home and email addresses, as well as phone numbers.
Verification documents (KYC - Know Your Customer): copies of passports or driver’s licenses, as well as selfies users took during account registration.
Financial details and history: IBAN numbers, bank statements, detailed transaction logs, and cryptocurrency operation history, including Bitcoin activity.
The company officially confirmed that biometric data in the form of facial scans for recognition (biometric facial telemetry) were not affected because they were simply not shared. Revolut also emphasizes that the company’s internal systems, applications, and clients’ funds remained secure — no money disappeared from accounts.
Scope of the problem and regulators’ response
The company does not disclose the exact number of affected clients yet, citing the secrecy of the ongoing investigation, but assures that a “limited number” of users were affected. According to blockchain researchers, including the well-known analyst ZachXBT, the attack was targeted and mostly affected users with a high level of capital.
As soon as specialists detected the forgery, the dangerous email address was immediately blocked. Reuters representatives reported that the company has already informed the relevant government agency (state authority) whose name was used by the attackers, as well as local police, data protection authorities, and financial regulators. All affected clients received personal notifications directly from the support service.
For Ukrainians using European financial services and who have previously faced identity verification requirements, such news is a reminder of the risks of the digital age. If you have not received direct notifications from your bank in your app, your account most likely was not on this list. However, protecting your finances will be helped by regularly checking your transaction history and carefully handling any requests regarding your personal data.


