Summary
- Revolut says it will cover affected customers’ identity document replacement costs.
- The incident exposed personal data belonging to 680 customers without compromising Revolut’s internal systems.
- Fraudulent requests impersonated an Italian government authority.
Revolut will cover the costs faced by customers who need to replace identity documents after personal information was released in response to fraudulent requests impersonating an Italian government authority.
The fintech says the incident affected 680 customers and did not involve attackers breaking into its internal systems. Instead, personal information was disclosed after requests arrived through an email address made to appear as though it belonged to a legitimate government body.
Béatrice Cossa-Dumurgier, Revolut’s chief executive for Western Europe, confirmed on Wednesday that the company would reimburse customers for expenses associated with replacing affected identity documents, although she did not give an estimate for the total potential cost.
That decision adds a remediation phase to an incident first disclosed in September, when Revolut said customer information had been released after apparently legitimate requests were received through a spoofed Italian government identity. Subsequent reports linked the data exposure to attempted extortion, while Revolut said it had not received a ransom demand directly.
Because the attackers exploited a disclosure process rather than breaking into the bank’s systems, the incident exposes a different security boundary from the one normally associated with account takeover. Banks and other regulated businesses routinely receive legitimate information requests from law enforcement agencies, regulators and other public bodies, creating workflows in which staff may need to release sensitive data outside ordinary customer access mechanisms.
If an attacker can convincingly reproduce the identity or communications channel of an authorised requester, controls around customer login security provide little protection. The decision instead depends on whether the organisation can establish that the authority making the request is genuine and that the information being sought falls within an authorised process.
Italy’s interior minister criticised Revolut over the checks carried out before the information was released. Revolut has maintained that its technology environment was not compromised and has argued that weaknesses in government communications can create risks for companies required to respond to official requests.
The exposure also creates a continuing identity risk for affected customers because information taken from government documents can support subsequent impersonation attempts. Replacing an identity document cannot reverse the original disclosure, but it can invalidate identifiers associated with a compromised document and reduce the value of some stolen information.
Similar trust problems arise in supplier impersonation, payment fraud and business email compromise, where an attacker targets the process surrounding an authenticated system rather than defeating that system directly. In each case, apparently legitimate context can persuade an employee or workflow to perform an action that the attacker could not carry out through the protected application itself.
Revolut’s reimbursement commitment addresses part of the direct cost to those customers, but the underlying incident also leaves questions about how sensitive government requests are verified before information is released. Any changes to those checks would need to preserve the ability to respond to legitimate authorities while making imitation harder to use as a route to customer data.
The company continues to maintain that customer funds and its internal systems were not breached, leaving the disclosure process rather than the banking platform itself at the centre of the incident.





