Breaches · 2h ago
Revolut confirmed that a fraudster used a legitimate government-domain email to pull sensitive records for a limited set of customers, moving the incident from allegation to confirmed disclosure on September 12. The company said the affected files came through its legal-request process, not its banking systems, and reports say the target set skewed toward high-net-worth and crypto-linked users.
The weakness was the trust check on the request itself: staff treated the message as an authentic government inquiry because the domain looked real, so Revolut released identity documents, contact details, account records, and in some cases transaction history that may include Bitcoin activity. That makes the haul useful not just for identity fraud, but for extortion and wallet deanonymization.
For banks, fintechs, and identity-verification teams that answer regulator or law-enforcement requests by email, the exposure lives in the disclosure workflow. If that workflow treats a real domain as proof, the sensitive data sitting behind it can still leave the organization even when core systems and customer funds stay untouched.
5 sources covering this story
Personal, Financial Info Exposed in Revolut Data Breach
The company unintentionally disclosed users’ information to a third party impersonating a government agency.
The Record from Recorded Future
Revolut handed customer data to fraudsters using government email account
British fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
Revolut Confirms Data Breach Through Fake Government Requests
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
What we know about the Revolut data breach so far - Help Net Security
Revolut data breach: fintech gave passports, selfies and bitcoin transaction histories to a scammer using a real government email domain.
Revolut confirms customer data breach through fake government requests | TechCrunch
Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.
Part of the PlainSec briefing for 2026-09-14