Revolut Data Breach Via Fake Government Requests – What We Know So Far

British fintech Revolut has confirmed a data breach in which an unauthorized third party obtained sensitive customer records by submitting fraudulent information requests through an email address using a legitimate government agency’s domain.

Unlike a conventional intrusion, the attacker did not have to exploit Revolut’s app or penetrate its core banking infrastructure. Instead, the operation abused trust in an apparently authentic government communication, causing customer data to be released through an established disclosure process.

According to Revolut’s notification to affected customers, the request originated from an unauthorized email account operating directly under the official domain of an unnamed government agency.

The message carried valid domain-authentication credentials, so Revolut handled it under the reasonable belief that it represented a genuine government request. The company has characterized the incident as a “sophisticated external impersonation scam” and says its systems and customer funds were not affected.

This distinction matters technically. SPF authorizes servers to send for a domain, DKIM applies a cryptographic signature, and DMARC tells receiving systems how to treat messages that fail those checks.

These controls can establish that an email passed through infrastructure authorized by a domain, but they do not prove that the person using an authorized mailbox is legitimate or that the request itself is lawful. If an attacker compromised or improperly obtained access to a real agency account, successful domain authentication would be expected rather than anomalous.

The affected-customer notice shows that the disclosed records could span nearly every major category of Know Your Customer data. Identity details included full names, dates of birth and occupations, while contact information included postal addresses, email addresses and telephone numbers.

Document and verification material included passport or driving-license copies and the facial image submitted during onboarding. Revolut stated that biometric facial telemetry was not involved or compromised.

Financial information may have included account statements containing IBANs, account status, opening dates and wallet reference numbers, alongside withdrawal records and complete transaction histories, including Bitcoin activity. TechCrunch separately reported that the data may have included verification selfies, account statements and transaction histories. This combination is particularly sensitive because it can connect a verified identity and home address to banking behavior, account identifiers and cryptocurrency holdings.

Revolut says only a “limited” number of customers were affected and that it contacted those individuals directly. The company has not disclosed the number of people involved, the government agency whose domain was abused, whether the incident was restricted to one country, how many fraudulent requests succeeded, or how long the activity continued.

147 GB of Data Exposed

Crypto investigator ZachXBT, who publicized the customer notification, assessed that the operation appeared to target high-net-worth users. Separately, International Cyber Digest reported claims from a threat actor using the name “IAmNotAVillain,” who alleged that multiple Italian law-enforcement departments had been compromised and that the Revolut operation lasted six months.

The actor also claimed possession of 147 GB of Italian-side material. Those allegations have not been independently verified and should not be treated as confirmed facts about the breach.

A screenshot circulated under the alleged actor’s watermark appears to show multiple archives named “Document Revolut,” email correspondence using an Italian certified-email address, and one extracted folder containing 688 files across 204 folders.

While the image is consistent with the broader allegation that formal law-enforcement channels were repeatedly abused, screenshots alone cannot establish authenticity, provenance, completeness, or the sender’s identity.

Revolut said it blocked the email address after detecting the scam and alerted the relevant government agency, law enforcement, data-protection authorities and financial regulators. It also contacted affected customers directly.

The company continues to underline that its systems were not breached and customer funds remain unaffected, but that assurance does not eliminate the downstream risk created by disclosing durable identity documents and detailed financial records.

For the financial sector, the incident highlights a structural weakness in government-data-request workflows: authenticated email should be one signal, not the final authorization control.

High-risk disclosures should require independent verification through a previously registered agency contact, case-number validation, requester authorization checks, dual approval, anomaly detection across repeated requests, and tamper-evident audit logs. Organizations should also apply strict data minimization, releasing only records that are legally necessary for a verified request.

Affected users should assume that criminals could use the exposed material for convincing bank impersonation, identity fraud, targeted phishing, SIM-swapping attempts or cryptocurrency-focused extortion. Any caller or message quoting accurate account details should still be treated as untrusted.

Customers should verify communication only through Revolut’s official app, strengthen email and mobile-account security, monitor statements and credit reports, and promptly report suspicious transactions or identity misuse.

The central lesson is that this was not simply an email-spoofing attempt. Based on Revolut’s account, trusted government infrastructure or an authorized path through that infrastructure was misused to defeat a human and procedural verification chain.

Until investigators identify the compromised agency, confirm the duration, and disclose the full victim count, the most important questions about scale and accountability remain unanswered over the coming weeks.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Revolut Data Breach Via Fake Government Requests – What We Know So Far appeared first on Cyber Security News.