Press play to start listening
Revolut, the London, United Kingdom-based global digital banking and financial technology platform, provided sensitive customer information to an unauthorized third party after being tricked by fraudulent requests sent through the legitimate email domain of a government agency.
The incident did not involve attackers breaching Revolut’s systems. Instead, the fraudulent requests came from an unauthorized email account using the government agency’s official domain and carried valid domain authentication credentials.
Revolut said it fulfilled the requests under the belief that they were authentic government requests. The company later contacted the government agency to verify the requests, which led to the discovery that the email account was unauthorized.
Passports, Selfies and Financial Records Disclosed
The information disclosed varied by customer but included highly sensitive identity and financial records. Revolut’s notification lists full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers.
Worse, copies of passports and/or driving licences were also disclosed, along with facial verification images provided during identity checks. Revolut normally collects identity documents and selfie images as part of its customer verification process.
The exposure was not limited to identity documents. The scammers also obtained detailed financial records, including account statements with IBANs, account status, opening dates and wallet reference numbers, along with withdrawal records and complete transaction histories, including Bitcoin transactions. Meanwhile, the fintech giant stressed biometric facial telemetry was not compromised in the incident.
Former Mt. Gox CEO Mark Karpelès was among the recipients of a Revolut notification and published excerpts from the email on X. Blockchain investigator ZachXBT also reported the incident, saying it appeared to affect a relatively small number of users and may have been directed at high-net-worth customers.
Revolut itself has not publicly confirmed that affected customers were selected because of their wealth. However, the company’s official support account responded to a query about the incident with a standard support response, stating, “We take data protection and privacy concerns very seriously.”
Hi there. We take data protection and privacy concerns very seriously. If you have any questions or need further assistance regarding this notification, please send us a DM via @RevolutSupport so we can look into this for you— Revolut Support (@revolutsupport) September 12, 2026
Government Agency Not Identified
Revolut has not identified the government agency whose domain was used. The company told Hackread.com that it had identified what it described as a “sophisticated external impersonation attack” involving an unauthorized third party using a legitimate government agency domain to submit fraudulent information requests.
After identifying the fraudulent activity, Revolut blocked the email address from its systems and alerted the affected government agency. The company also notified police, financial and data protection regulators, and affected customers. Revolut said its systems and customer funds were unaffected.
The company has not disclosed how many fraudulent requests it processed, how many customers were affected, when it provided the information, or whether the attacker used the stolen records elsewhere.
The incident is therefore different from a conventional data breach in which attackers gain unauthorized access to a company’s infrastructure. In this case, the available evidence indicates Revolut itself released the information after accepting fraudulent requests as legitimate.
The exposed combination of identity documents, contact details, and financial histories could also provide information useful for highly personalized phishing or impersonation attempts. Revolut advises customers receiving suspicious communications not to disclose financial information and to contact the company through official channels.
Revolut and Cybersecurity Issues
This is not the first security-related incident involving Revolut. In 2023, Hackread.com reported that criminals exploited a flaw in the company’s US payment system, causing about $23 million in losses before some funds were recovered, leaving Revolut with a net loss of about $20 million. The flaw caused declined transactions to be incorrectly refunded using Revolut’s own money.
Revolut was also among the companies targeted by hackers associated with Lapsus$. During a 2023 UK trial involving Arion Kurtaj and another teenager, prosecutors detailed attacks against several major companies, while evidence presented in the case showed that Kurtaj had hacked Revolut and Uber while on bail.
(Photo by Aleksandrs Karevs on Unsplash)
