Cyber Threat Intelligence, Entrepreneur, Presentation Virtuoso

Nobody Broke Into Revolut, They Just Asked

Revolut handed a stranger its customers passports, selfies, and full transaction histories. Nobody broke in. A fraudster asked, using a legitimate government email domain, and Revolut said yes. No hack, no exploit, just an email and a lie, and the trust a bank extends to anything official.
Nobody Broke Into Revolut, They Just Asked

revolut just handed a stranger its customers' passports, selfies, and full transaction histories. nobody broke in. it was one of the oldest tricks in the book. social engineering. the kevin mitnick hacking strategy. the attacker simply asked, using a government email address, and revolut said yes without blinking.

as a revolut customer myself, this is concerning af. why are they unquestionably handing over customer data? there ought to be some due diligence before blindly handing out personally identifiable information to any government.

this was not a hack. there was no intrusion, no exploit, no malware. a fraudster simply sent requests for customer information from a legitimate government agency email domain. revolut, seeing what looked like an official government request, fulfilled it. without question. does revolut not have in-house lawyers? at the worst, using ai for some level of legal counseling?

the entire attack was an email and a lie.

look at what that email pried loose. full know-your-customer (kyc) files. names, dates of birth, addresses, phone numbers. copies of passports and driver's licenses. verification selfies. account statements, ibans, withdrawal records, and complete transaction histories, bitcoin included. everything a bank collects to prove you are you, handed to someone pretending to be the government.

generally speaking, threat actors will attempt to break something. they need a vulnerability, a stolen password, a phishing click, some technical foothold. this attacker needed none of that. straight up, pure play social engineering, the old fashioned way.

they merely needed the trust most companies almost automatically extend to a request appearing to come from the government. that trust is the vulnerability, and it cannot be patched with software.

to be clear, this is not just a revolut problem. it is an industry-wide issue. law enforcement calls them "emergency data requests" aka edr. it is a legitimate legal mechanism where police or agencies ask a company for user data urgently. in a genuine emergency, these requests can bypass the normal warrant or subpoena process because exigent circumstances are allegedly at stake.

the fbi warned back in 2024 that criminals were buying and compromising real government email accounts specifically to forge these requests. so the exact scam that hit revolut was flagged as a growing threat two years ago, and here we are.

think about the asymmetry. to get your data the legal way, a government needs process, oversight, sometimes a judge. to get it the fraudulent way, an attacker needs one compromised .gov inbox and the balls to ask. the same trust letting law enforcement move fast in a real emergency is the trust a criminal exploits to move fast in a fake one. the feature and the vulnerability are the same thing.

the attackers posted the stolen data in telegram channels. it reportedly included ceos, athletes, and performers. it is plausible this was not some random pull, but potentially something targeted. it may have been reconnaissance on specific high-value people, using revolut as the unwitting supplier. for me, i find that truly unsettling. this may not have been data stolen to dump or sell, but data extracted for targeting.

so where does this leave the average joe? mostly powerless. you did everything right. you gave your bank your id because you had to. the failure was not yours. it was one person inside a company deciding a convincing email was authorization enough.

the question every regulated firm should be forced to answer is simple. who inside your walls can release a complete file on a customer, and on whose word? because at revolut, the answer turned out to be, anyone with a government email address and a good story.

you were never really trusting your bank to guard your identity. you were trusting that no one would ever ask for it convincingly enough.

revolut did not lose control of the vault. someone knocked on the front door wearing a government badge, asked for the contents, and revolut carried the boxes outside for them.

the breach was not technical. the authorization was.