$ techbeacon▋
Ransomware

Revolut Discloses Customer KYC Files After Phishing Email Bypasses Security Protocols

Revolut Discloses Customer KYC Files After Phishing Email Bypasses Security Protocols

Revolut announced on September 12, 2026 that it unintentionally released a suite of customer verification records to an unauthorised party after a counterfeit government email passed the company's identity‑checking safeguards.

The deceptive message, which appeared to originate from a legitimate government domain, requested standard know‑your‑customer (KYC) documentation. In response, Revolut supplied scanned IDs, facial selfies and even Bitcoin transaction histories that had been collected for compliance purposes.

Financial‑technology firms gather such data to satisfy anti‑money‑laundering regulations and to confirm that account holders are who they claim to be. The information typically includes government‑issued photo IDs, proof of address, and, for crypto‑enabled users, a record of recent blockchain activity.

According to the company, the email’s domain credentials were technically valid, allowing it to slip past automated verification filters that normally flag suspicious requests. Security analysts note that sophisticated phishing campaigns often exploit the trust placed in government‑issued email addresses, making it difficult for even well‑resourced platforms to differentiate legitimate inquiries from fraudulent ones.

In its public statement, Revolut said it had launched an internal investigation, tightened its email‑authentication procedures and notified affected customers of the breach. The firm also pledged to work with regulators to assess any potential compliance gaps and to provide support for users who may be at heightened risk of identity theft.

The incident arrives at a time when data‑protection authorities across Europe are intensifying scrutiny of fintech providers under the General Data Protection Regulation and sector‑specific rules. Regulators could impose fines if they determine that the company failed to implement adequate safeguards or to report the breach within mandated timeframes.

Industry observers warn that the episode underscores a broader vulnerability in the fast‑growing crypto‑service market, where the convergence of traditional finance and digital assets creates a larger attack surface for social‑engineering attacks.

Law enforcement agencies have opened separate inquiries to trace the origin of the fraudulent email and to identify any downstream misuse of the leaked records. Experts suggest that affected customers should monitor their accounts for unusual activity and consider updating authentication methods.

Revolut’s disclosure adds to a growing list of high‑profile data incidents that highlight the need for more robust verification frameworks, especially as financial services continue to integrate blockchain‑based features. The outcome of regulatory reviews and potential legal actions will likely shape how fintech firms balance user convenience with stringent security controls going forward.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related