REVOLUT confirmed on 12 September 2026 that it disclosed sensitive customer information to an unauthorised third party after processing a fraudulent request sent from an email account operating within a genuine government agency’s domain infrastructure. The message carried valid domain-authentication credentials and therefore passed the checks used to establish that it came from the authority.
Revolut said it acted on the reasonable belief that the request was genuine and discovered the fraud only after independently contacting the agency, which denied sending it.
The affected data reportedly included customers’ names, dates of birth, occupations, postal and email addresses, telephone numbers, passport or driving-licence copies, verification selfies, account statements, IBANs, account status, opening dates, wallet reference numbers, withdrawal records and full transaction histories, including Bitcoin. Revolut said no biometric facial telemetry was involved.
It described the incident as affecting a limited number of customers, but did not provide a figure or identify the government agency or market concerned. Researcher ZachXBT assessed that the operation appeared to target high-net-worth users, although this remains an assessment rather than a confirmed finding.
Revolut said its systems and customer funds were not affected. It blocked the email address, alerted the agency, notified law enforcement and reported the incident to financial regulators. The company said the incident did not involve an outsider compromising its servers or using malware; instead, the attacker appears to have used a compromised or fraudulently created account within the government domain to submit a convincing data request. Revolut said it had contacted affected customers.