Search
Choose a style
Dark
Light
Time to read: 4 min

Revolut data leak sparks urgency vs security debate

Revolut logo in London.
Source: Revolut

Revolut’s recent data breach has led the industry to question whether pressure to respond quickly to official requests can weaken verification checks.

Revolut sent sensitive customer information to an unauthorised third party, believing it was responding to a legitimate government request.

The UK-based fintech received requests through a government agency email domain and treated them as genuine, the bank confirmed on 12 September. 

Affected data included passports, driving licences, verification selfies, home addresses and transaction histories, including full bitcoin transaction records.

Revolut said the leak affected a limited number of customers, but hasn’t disclosed the exact number of people involved, which government agency was impersonated or whether the incident was limited to a particular market. The company stressed that its systems weren’t breached and customer funds remained safe.

Passports, selfies and addresses are used during Know Your Customer (KYC) checks to verify a person’s identity and transaction histories show how they move money, including through bitcoin.

This information could potentially be used for impersonation, social engineering or highly targeted fraud attempts. There’s also the risk of identity documents being reused elsewhere, including attempts to open accounts, pass verification checks or target victims across other financial services.

According to figures from fraud prevention service Cifas, more than 220,000 fraud-risk cases were recorded in the UK National Fraud Database (NFD) between January and June, the highest volume ever for the first six months of a year.

Revolut headquarters building in Canary Wharf, London, UK on 24 April 2025.
Editorial credit: WD Stock Photos / Shutterstock.com

How the leak happened

Revolut received requests for customer information from an email address using a legitimate government agency domain, making the messages appear to be an official request.

The requests passed Revolut’s checks and customer information was released. The fintech later contacted the government agency and discovered that the person behind the requests wasn’t authorised to make them.

Revolut has not explained how the third party was able to use the legitimate government domain, making it unclear whether an account was compromised or another method was used.

A company spokesperson described the incident as an “external impersonation scam” and said the challenger bank blocked the address once the problem was discovered. Revolut also contacted the government agency involved, law enforcement, data protection authorities and financial regulators.

When urgency becomes a weakness

In a LinkedIn post, Jonathan Frost, a global advisory director at the behavioural-intelligence firm BioCatch, said that Revolut isn’t alone in facing this type of attack.

Jonathan Frost, Biocatch on UK gambling
Jonathan Frost, BioCatch – Source: LinkedIn

He highlighted previous cases involving Apple, Meta and Discord, where hackers used compromised law enforcement email accounts to submit fraudulent requests for user information.

“The common thread is that attackers don’t need to breach your systems,” Frost wrote. “They only need a channel your process treats as trusted.”

He said legal and emergency information requests can create a problem because institutions are expected to respond quickly.

“Domain authentication proves a message came from a real mailbox. It proves nothing about who’s typing,” Frost added.

Manoj Bhura, Senior Manager at Protiviti UK
Manoj Bhura, Senior Manager at Protiviti UK – Source: LinkedIn

Manoj Bhura, Senior Manager at Protiviti UK, also questioned whether Revolut should have used an independent verification step before releasing customer information.

He suggested that financial institutions could contact the requesting agency through a previously verified channel rather than relying only on the information contained within the request.

However, Bhura also raised a concern about whether pressure to respond quickly to official requests can weaken checks.

“Or is the deeper issue: fintech companies face institutional pressure to respond quickly to government requests, which creates a bias toward action over verification?” he wrote on LinkedIn.

Subscribe to our newsletter