Data Breaches · Phishing / BEC

Revolut Data Leak Came Through Trusted Email

Revolut confirmed that a fraudster used a legitimate government-domain email to pull sensitive records for a limited set of customers, moving the incident from allegation to confirmed disclosure on September 12. The company said the affected files came through its legal-request process, not its banking systems, and reports say the target set skewed toward high-net-worth and crypto-linked users.

The weakness was the trust check on the request itself: staff treated the message as an authentic government inquiry because the domain looked real, so Revolut released identity documents, contact details, account records, and in some cases transaction history that may include Bitcoin activity. That makes the haul useful not just for identity fraud, but for extortion and wallet deanonymization.

For banks, fintechs, and identity-verification teams that answer regulator or law-enforcement requests by email, the exposure lives in the disclosure workflow. If that workflow treats a real domain as proof, the sensitive data sitting behind it can still leave the organization even when core systems and customer funds stay untouched.

5 sources · 4h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-14

Every edition of this story: Revolut Data Leak Came Through Trusted Email

More from today