Revolut treated a spoofed agency email as a lawful data request

A forged request sent from inside a real government domain was enough to pull identity documents, selfies, and Bitcoin histories out of the fintech.

CSBadmin
2 Min Read

Identity verification files are only as safe as the process that hands them over. Revolut’s process was fooled this month, and customer records walked out the door.

An attacker sent the fintech a request for customer information from a mailbox inside a real government agency’s domain. The message carried valid domain authentication credentials, the check meant to prove an authority sent it. Staff complied.

The bundle that left covered nearly everything a regulated platform must collect: names, birth dates, postal and email addresses, phone numbers, passport and driver’s license images, verification selfies, account statements, and full transaction histories. Several outlets confirmed those histories covered Bitcoin.

There was no intrusion and no malware. The sender either created a rogue account on the agency’s domain or hijacked an existing one, then filed what looked like routine legal paperwork. Only after Revolut called the agency did it learn the request was never made.

Revolut described the impact as limited. It has not said how many customers were affected, and it declined to name the agency or the country involved. That omission matters: without the mailbox, other regulated platforms cannot check their own request logs for the same sender.

The takeaway for compliance teams is uncomfortable. Domain authentication proves a sender is real, not authorized. Requests for identity documents deserve an out-of-band callback to a known contact before a single file is released.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.