Revolut, the British fintech giant, just got caught by one of the oldest tricks in the cybercrime playbook: a well-crafted fake email.

The company publicly confirmed on September 12 that it had disclosed sensitive customer information after receiving fraudulent data requests sent from an email address impersonating a legitimate government agency. The spoofed messages were good enough to pass SPF, DKIM, and DMARC authentication checks, which are essentially the three-layered security system email servers use to verify that a message actually comes from who it claims to come from.

What was exposed and who was targeted

The compromised data included full names, birth dates, contact information, copies of identification documents, transaction histories, and account statements. Revolut stressed that no biometric facial telemetry data was shared during the incident. The company also maintained that no customer funds were stolen and that its core banking systems were not compromised.

Revolut has not disclosed the exact number of affected users. Reports suggest that a select group of higher-net-worth individuals may have been specifically targeted. On-chain analyst ZachXBT indicated the incident appeared to be limited in scale.