Written by Admin Alex · Fact-Checked by M.Ali · Info Verified September 2026
We review and update this article regularly as new information becomes available.
TL;DR: Revolut confirmed on September 12, 2026 that customer data was exposed after someone impersonated a real government agency using its actual email domain. The fake request looked like a legally binding demand for records, and it worked. Names, birth dates, ID documents, verification selfies, addresses, and transaction histories, including crypto activity for some users, got out before Revolut caught it.

No malware. No hacked server. Just an email that looked exactly like it came from a real government agency, because it did.
That is the part that should worry anyone who banks with Revolut, and honestly anyone who banks anywhere. This was not a breach of the app or the servers holding your money. It was a breach of trust between a fintech’s compliance team and the government bodies it is legally required to cooperate with.
How the fake request actually worked
Here is what “spoofing a government domain” means in practice, stripped of the jargon. Regulators and law enforcement agencies routinely send financial companies legally compelled requests for customer information. Revolut’s compliance staff are trained to respond to these, because ignoring a real one can mean fines or worse.
An unauthorized third party got hold of, or somehow used, the legitimate email domain belonging to a real government agency. They used it to submit what looked like an official records request to Revolut’s customer service and compliance team. Revolut has not said which agency’s domain was involved or which markets were hit.
This is not the phishing email your employees get trained to spot. There is no shady link to hover over. No urgent password reset. No obviously misspelled sender address. It arrives from a domain that genuinely belongs to a government body, asking for exactly the kind of information a company is supposed to hand over when asked. Standard fraud training teaches people to distrust suspicious links and unfamiliar senders. It does not teach people to distrust a legal compliance request that appears to come from the correct place. That gap is exactly what got exploited here.
What data actually got out
Per Revolut’s own disclosure, the exposed information included birth dates, postal addresses, email addresses, and phone numbers. It also included identity documents: passports and driver’s licenses. Verification selfies, the kind used to confirm you are the person on the ID, were exposed too. So were account statements and full transaction histories, and for some users that included Bitcoin and other crypto activity.
That is close to a complete identity package. Combine a real ID photo, a selfie, an address history, and a transaction record, and you have most of what a criminal needs to impersonate someone convincingly, not just to open a fraudulent account somewhere else, but to talk their way past a bank’s own verification desk.
How many people, and who
Revolut has declined to give a number, calling the scope “limited” and nothing more specific. Independent crypto investigator ZachXBT has suggested the incident hit high-net-worth users disproportionately. Neither Revolut nor ZachXBT has offered a count, and we are not going to guess one either.
Revolut’s response
Revolut says it blocked the fraudulent email address as soon as it was identified, notified the customers affected directly, and alerted the real government agency whose domain was misused, along with law enforcement and financial regulators. The company put it this way: “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government domain email” to submit the fraudulent requests.
Revolut also says the core banking systems were never touched and customer funds are safe: “Revolut systems and customer funds are unaffected.” That is a real distinction. Nobody’s balance moved. But money sitting untouched in an account is a low bar when someone out there may be holding your passport scan and your selfie.
What to watch for if you bank with Revolut
If Revolut has contacted you directly about this, take it seriously, and treat anything else that lands in your inbox afterward with suspicion.
Expect follow-on phishing that references real details from your account, since a message that gets your address or a past transaction right feels far more credible than a generic scam email. Watch your phone account closely too. Exposed phone numbers paired with real identity documents are exactly what makes a SIM-swap attempt easier to pull off, and a successful SIM swap can unlock two-factor codes for your other accounts, not just Revolut.
Be wary of anyone calling or emailing you claiming to be from Revolut, a regulator, or law enforcement and asking you to “verify” details or move funds to a “safe” account. That is social engineering built on leaked data, and it works precisely because the caller already knows things a stranger shouldn’t. If you hold crypto through Revolut, keep a closer eye than usual on wallet activity and consider that transaction history tied to your real identity is no longer private information.
Bottom Line
The scary thing about this breach is not the technology. There wasn’t much. It was a fake letter that looked real enough to fool the people whose entire job is checking whether requests like it are legitimate. Fintechs love to talk about how secure their apps and encryption are, but this incident is a reminder that the weakest point in a financial company’s defenses is often a human process, not a firewall. If a spoofed government domain can extract passports and selfies from a company Revolut’s size, every bank and fintech handling this kind of data needs to be asking how they’d catch the same trick, not assuming they already would.

