Revolut phishing attack bypasses email security, exposes customer data
In brief
- Spoofed email bypassed SPF, DKIM, and DMARC authentication protocols
- Exposed data: ID documents, selfies, names, dates of birth, transaction records
- Attack targeted Revolut's compliance workflow, not core systems
- Passwords, PINs, funds, and private keys remained secure
How the attack worked
The fraudulent email passed SPF, DKIM, and DMARC checks — the three email authentication protocols that organizations rely on to verify sender identity. SPF confirms the email came from an authorized server. DKIM verifies the message wasn't tampered with in transit. DMARC ties them together and tells the recipient what to do if either check fails.
Revolut's compliance team had every technical reason to believe the request was genuine. They processed it, handing over customer records to an unauthorized third party who had essentially forged perfect credentials without ever touching Revolut's internal systems.
This wasn't a zero-day exploit or a compromised database. It was social engineering targeting Revolut's compliance workflow for responding to official government data requests.
What was exposed
The exposed data included identity documents, verification selfies, full names, dates of birth, contact information, and financial records including IBANs and withdrawal histories. Bitcoin-related transaction activity was also included.
The combination is particularly damaging. Cryptocurrency transaction data, combined with identity documents and verification selfies, gives bad actors a toolkit for identity fraud, social engineering, or targeted phishing campaigns.
Company response and implications
Revolut characterized the incident as a sophisticated external impersonation scam. The company described the number of affected customers as "limited," though it has not disclosed the exact figure. Revolut blocked the unauthorized email address and notified both law enforcement and relevant regulatory agencies. The company confirmed that its systems remain uncompromised and that no customer funds were affected.
The breach arrives at a particularly sensitive moment. Revolut has been actively pursuing a banking license and a public listing. Regulatory scrutiny over data security and incident response will likely intensify. The incident exposes a vulnerability that extends beyond Revolut — email authentication protocols, while robust on paper, can be circumvented through social engineering targeting the human operators who receive them. For fintech firms handling sensitive customer data, that gap between technical verification and operational judgment is where risk lives.


