Revolut has acknowledged that fraudsters obtained sensitive customer information by submitting false emergency data requests through a legitimate government email address. The attackers appear to have focused on affluent individuals, particularly those with involvement in cryptocurrency businesses.

The fintech disclosed over the weekend that it "recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information." The company did not name the specific government domain involved, though evidence posted on Telegram by an account claiming responsibility for the attack points to an Italian government email address.

Multiple Italian government bodies approached for comment by Recorded Future News did not respond. The Telegram account responsible for publicizing the breach has since been taken down, and not all claims made in its posts have been independently verified.

At least one Revolut customer whose data appeared in the Telegram posts confirmed the authenticity of the leaked information through a social media statement. Revolut stated that the number of affected customers was small and that it had reached out to them directly.

"Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators," Revolut said in a statement.

It remains unclear whether the same compromised email account was used to target other financial institutions. The perpetrators demanded an extortion payment from Revolut in exchange for not releasing the customer data publicly. Revolut declined to address questions about whether an extortion demand was made.

Cryptocurrency entrepreneur Marc Zeller posted on X that he discovered on Saturday that "all my data leaked by Revolut." He added, "The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or 'we will close your account in 20 days'. Now we know they been fooled by hackers and did all the work for them like good little lap dogs."

According to customer notices shared by affected individuals, the exposed data encompasses birth dates, mailing and email addresses, phone numbers, copies of passports and driver's licenses, identity verification selfies, bank statements, international bank account numbers (IBAN), withdrawal records and transaction histories, including Bitcoin transactions.

Mark Karpelès, former chief executive of the Mt. Gox bitcoin exchange, was among those reporting that their information had been compromised.

Similar incidents occurred in 2021 and 2022 when the Lapsus$ group deployed compromised law enforcement credentials and fabricated emergency data requests to extract user data from major technology firms such as Apple, Meta and Discord.

The FBI has previously warned about fraudulent emergency data requests, citing "an increase in postings on criminal forums" where access to compromised email accounts is offered for conducting such attacks.

Revolut operates with more than 80 million customers worldwide and is exploring a public listing that could reach a valuation of up to $200 billion.