Revolut hands over the details of 700 customers to fraudsters. The Italian lead
The British fintech company has alerted the users concerned. The fraudulent request, which appeared to come from a government body, may actually originate from our country
3' min read
3' min read
Imagine receiving an email from your bank informing you that your personal details, contact addresses, identification documents and financial details (including your transaction history) are now in the hands of a hacker.
This is what happened to several customers Revolut, with the number estimated at just under 700 people. The British fintech company has notified the affected users by email: ‘We are contacting you to inform you of a recent security incident, involving an external identity theft that resulted in some of your personal data being shared with an unauthorised third party.’
What happened
Revolut stated that it had received a request to share its customers’ data from an account that appeared to belong to a government body. The company proceeded to forward the requested information, in accordance with the GDPR (General Data Protection Regulation). Under the European regulation, a company is required to disclose its customers’ personal data if the request from the government body is binding, formally legitimate and based on specific legal provisions (such as investigation orders or warrants).
“The procedure for a government agency to request data is called an ‘emergency data request’, and all platforms (social networks, cloud providers) handle dozens of them every day,” explains Marco Ramilli, founder of the Italian cyber intelligence firm Yoroi.
The problem? The person who made the request was not actually a public authority. The hackers were posing as someone else, using an email address that actually belonged to a government body’s email domain and therefore had valid authentication credentials.

