
Fintech firm Revolut exposed sensitive user information, including IDs and transaction histories, after falling for a fraudulent request sent from a legitimate government domain.
Fintech company Revolut exposed sensitive customer data including IDs and transaction histories after receiving a fraudulent information request from a spoofed government email domain.
AI-generated summary
Revolut received a fraudulent request from a legitimate government agency email domain, leading to the release of customer data.
Financial tech and banking company Revolut released sensitive customer data, including copies of passports, verification selfies and full transaction histories after receiving a fraudulent request that seemed to be from a government agency.
Requests for customer information sent from a legitimate government agency email domain passed Revolut’s authentication checks, according to International Cyber Digest posting on X. Revolut later concluded they were not authentic, and customers whose information was compromised were notified on Friday.
A company spokesperson told Cointelegraph on Saturday that “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
The spokesperson added that upon detection, Revolut blocked the address and alerted the relevant government agency. It also notified enforcement agencies and financial regulators.
“Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support,” the spokesperson said.
Crypto sleuth ZachXBT reportedly said he thought the incident was limited in size and aimed at high-net-worth users.
The incident caused a stir on X that saw some users criticizing the prevailing system of mandatory information sharing. Marc Zeller wrote that he woke up to all his data being leaked by Revolut, adding: “Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way.”

Under the EU's Cyber Resilience Act, manufacturers of connected hardware wallets and software must report actively exploited vulnerabilities or severe security incidents to cyber authorities within 24 hours, effective September 11, 2026.

Anthropic CEO Dario Amodei warned that rapid AI development risks outrunning human control through recursive self-improvement, proposing international safety standards supported by OpenAI CEO Sam Altman.

The XRP Ledger has activated the fixCleanup3_3_0 amendment, introducing maintenance updates for transaction handling and AMMs. Servers failing to support the new rules risk becoming amendment-blocked, necessitating software updates for infrastructure operators.

OpenAI's new ChatGPT Images 2.5 model is compared against Google's Nano Banana 2. While OpenAI resolved previous oversharpening issues, the models remain closely matched in performance, with each showing specific strengths in text rendering, spatial awareness, and factual accuracy.

Greenberg Traurig reported an unauthorized actor accessed and posted limited documents on the dark web, exposing client Social Security information. The breach is part of a growing trend targeting law firms, with BakerHostetler handling nearly 60 cybersecurity incidents in 2025. Other firms including Taft Stettinius, Herbert Smith Freehills, WilmerHale, Goodwin Procter, and Quinn Emanuel disclosed breaches. Crypto companies Coinbase, Ledger, and SafePal also reported customer data exposures.

OpenAI has consulted members of Congress on whether rival AI companies could legally agree to slow development, following internal calls for shared safety standards amid intense commercial and geopolitical competition. The outreach comes as researchers warn of pressure to cut corners on safety, with concerns that unilateral slowdowns put companies at a competitive disadvantage without industry-wide coordination.