Revolut, a British online banking and financial services company with 80 million customers globally, may have transmitted sensitive customer data in response to what it believed were legitimate government requests. This revelation comes from a whistleblower and was reported by FrenchBreaches on Saturday, September 12. The data potentially included personal information such as names, dates of birth, phone numbers, and addresses, as well as more sensitive details like passport copies, selfies used for identity verification, and full transaction histories, including Bitcoin activity. The breach reportedly began with emails sent from what appeared to be an authentic administrative domain. This allowed malicious actors to bypass Revolut’s usual security filters. Unlike a traditional server breach, where hackers would directly access a system, this attack relied on social engineering and deception. The malicious actor obtained an email address from an official-looking administrative domain, which passed Revolut’s automatic checks as legitimate. As a result, the requests were treated as official, and the company transmitted the requested data before later blocking the suspicious address and informing both the impersonated administration and regulatory authorities. Affected customers began receiving personal notifications starting on Friday, though the exact number of people impacted remains unclear. According to ZachXBT, a cryptocurrency researcher, the attack may have specifically targeted customers with significant financial assets, suggesting a possible financial motive. This raises concerns about the potential misuse of the transmitted data for identity theft or further phishing attacks. Revolut has not yet confirmed or denied the financial motive behind the operation. Questions remain about which government or administrative body was impersonated, how the malicious actor obtained an official-looking email address, and the precise number of affected accounts. The incident highlights the growing risks of sophisticated phishing attacks and the importance of verifying the legitimacy of requests, especially those involving sensitive personal or financial data.