Published: Sep 14, 2026 at 20:11
Updated: Sep 14, 2026 at 20:21
Digital banking giant Revolut became the center of a major cybersecurity controversy following a sophisticated social engineering and data exposure incident.
Rather than a traditional software hack or network intrusion, the breach occurred because the company fell victim to an external impersonation scam that manipulated standard legal compliance procedures.
The Fake Government Inquiry
The security event unfolded when bad actors utilized a legitimate government agency domain email address to submit fraudulent, urgent requests for customer information. Because the requests carried valid technical domain credentials and passed email authentication checks (such as DKIM), Revolut’s compliance systems treated them as authentic, lawful law enforcement inquiries.
Under strict legal obligations to cooperate with official government and regulatory probes, compliance teams inadvertently handed over a trove of sensitive data belonging to a targeted subset of users—predominantly high-net-worth individuals and crypto-focused accounts.
Exposed records included full names, dates of birth, postal addresses, email addresses, phone numbers, occupations, copies of passports or driver’s licenses, and verification selfies. Revolut serves over 80 million customers globally.
Attackers also obtained sensitive financial histories, including IBANs, account statements, withdrawal records, and complete transaction histories detailing Bitcoin and alternative asset activity.
Extortion Threats
Following the incident, a hacker group calling itself “Revolut Smilik” began circulating portions of the stolen data on Telegram, attempting to extort the company with threats of leaking further customer documents if demands weren’t met. Notable figures within the crypto community, including prominent entrepreneurs and former exchange executives, confirmed that their personal details were among those compromised.
Revolut has maintained that its core internal databases, technical systems, and customer funds remain entirely safe and unaffected. Upon discovering the fraud, the company immediately blocked the malicious email address, notified affected individuals directly, and alerted data protection authorities, financial regulators, and law enforcement.
Agencies such as the UK’s Financial Conduct Authority (FCA) and the Information Commissioner’s Office (ICO) quickly opened inquiries to evaluate the breach and determine compliance liabilities.
Security experts note that this incident underscores a critical vulnerability in institutional trust architectures: even when core software security is ironclad, human-centric social engineering exploiting verified communication channels remains a devastating vector for targeted data theft.
Disclaimer. The data provided is collected by the author and is not sponsored by any company or token developer. This is not a recommendation to buy or sell cryptocurrency and should not be viewed as an endorsement by Coinidol.com. Readers should do their research before investing in funds. Brought from CoinIdol.com.





Be the first to comment