The request carried genuine credentials that had previously passed the company's checks, CoinDesk reported. Revolut treated it as legitimate and released the information.
Only afterwards did bank representatives contact the agency whose name appeared on the email. The agency said it had sent no such request. Revolut blocked the fraudsters' address and sent warnings to affected customers.
According to TechCrunch, the attackers obtained customers' dates of birth, postal and email addresses, phone numbers, occupations, and copies of identity documents - passports or driver's licences - along with selfies used for identity verification, account statements and transaction histories. Account numbers (IBAN) may also have been exposed.
Customer funds and biometric data were not affected, the bank said. Revolut has not disclosed how many users were involved, nor specified which government body was impersonated or in which country the request originated.
A blockchain researcher known as ZachXBT said the attack was probably aimed at the bank's wealthiest clients. In his account, the scale of the leak was minor.