🇵🇹 Portugal news, in English, every morning. Free. Subscribe

Impostors Emailing From a Real Government Domain Got Revolut to Release Customer Files on 680 Accounts

The bank confirmed on Wednesday that it answered fraudulent information requests sent from a legitimate public authority's email domain. Addresses, verification photographs and identity documents went out. Revolut will not say whether Portuguese clients are among them.

Impostors Emailing From a Real Government Domain Got Revolut to Release Customer Files on 680 Accounts

Revolut confirmed on Wednesday that it handed customer information to a third party posing as a government agency, in what the company describes as a sophisticated impersonation scheme. No systems were breached and no money moved. What the attackers took was identity data, and they took it by asking for it in a way that looked lawful.

"Revolut recently identified a sophisticated third-party impersonation scheme, in which an unauthorised entity used an email address with the domain of a legitimate government agency to send fraudulent requests for information," a spokesperson for the banking group told Lusa. "As soon as the situation was detected, the address was immediately blocked and the relevant government agency was alerted, along with law enforcement, the data protection bodies and the financial regulators."

The company says a "limited number of people" were affected, that Revolut's systems and client funds were untouched, and that the clients concerned were contacted directly and offered support.

What was exposed, and to whom

A source close to the process cited by AFP puts the number of affected clients at 680. According to the Financial Times, the data concerned includes addresses, verification photographs, identity documents and information relating to bitcoin activity. The newspaper says it contacted the hackers who claim to be behind the incident, and that they exchanged emails with the bank over several months under the false identity.

The selection of targets is the telling part. The clients hit are holders of significant volumes of crypto assets, particularly in Switzerland and France. That is not a random sweep of a customer database; it is a shortlist, assembled by people who knew which requests to make and which authority to impersonate while making them.

Britain's Information Commissioner's Office confirmed to AFP that it has received a report and is analysing the information supplied.

The Portuguese question Revolut will not answer

Revolut has not confirmed whether any Portuguese clients are among those whose data was exposed. That silence matters more here than in most markets. The company counts 2.3 million clients in Portugal, a figure it uses to claim the position of third-largest bank in the country by customer numbers, and it is the default account for a large share of foreign residents who arrive before they have a Portuguese bank relationship.

On the company's own account, anyone affected has already been contacted individually, which means clients who have heard nothing are not on the list. Residents who believe their personal data has been mishandled can complain to the Comissão Nacional de Proteção de Dados (National Data Protection Commission), the Portuguese supervisory authority, though the lead regulatory interest in this case sits outside Portugal.

The practical exposure for anyone caught up in it is identity fraud rather than theft from the account. Addresses, photographs and identity documents are the raw material for opening credit elsewhere or for a convincing follow-up approach by telephone or message, and a caller who can recite your address and document number sounds a great deal more official than one who cannot.

A method, not a break-in

Nothing in this incident required breaking a system. It required an email domain that belonged to a real public authority and the patience to keep a correspondence going for months. Banks are legally obliged to answer requests for information from public authorities, and that obligation is exactly what was aimed at.

It lands in a fortnight when Portuguese infrastructure has been tested from another direction: MEO said on Monday that a mass attack had degraded its international network, days after the telecoms regulator opened rulemaking on the sector's cybersecurity obligations.

Founded in 2015 and now carrying more than 80 million customers worldwide, Revolut built its reputation on currency conversion and cheap transfers done from a phone. The speed of that expansion has drawn repeated questions about its capacity to meet financial regulation, particularly on fraud and money laundering. This week's episode adds a different question, and not only for Revolut: how a bank verifies that the government asking for your file is the government.