An Impostor Used a Real Government Email to Get Revolut’s Customer Records
Revolut did not report an intruder breaking into its banking systems. It disclosed customer information after a fake government request arrived from an email address on a genuine agency domain. The distinction matters: the attacker appears to have used an apparently trusted channel to make an unauthorised request look official.
The company confirmed the disclosure to TechCrunch and Reuters on 12 September 2026. It says its systems and customer funds were unaffected. It has not disclosed how many people were affected, identified the government agency or explained how the third party gained use of an address on that agency’s domain.
What the fake government request obtained
TechCrunch reviewed a notice sent to affected customers. It says the exposed information included dates of birth, postal and email addresses, telephone numbers and copies of identity documents such as passports or driving licences. Revolut’s notice said verification selfies, account statements and transaction histories may also have been included. Those categories are not proof that every affected person’s file contained every item.
This is a particularly sensitive combination. Identity documents and selfies can support convincing impersonation. Account statements and transaction histories can reveal where someone lives, works, travels or sends money. A criminal who has that context can make a later message sound like a legitimate bank, tax or law-enforcement enquiry. The risk does not require the attacker to move funds directly from a Revolut account.
Revolut described the fake government request as an external impersonation scam. It says it blocked the email address after identifying the fraudulent requests, notified affected customers, and alerted the relevant government agency, law enforcement and regulators. The bank did not say precisely when the requests were sent, when the data was released, how many separate requests were involved or which verification step failed.
Why a fake government request looked authentic
An email from a real government domain is stronger evidence than a lookalike domain, but it does not establish that the person using the mailbox is authorised to seek a particular customer’s records. An agency account may be compromised, misused or otherwise accessed by an unauthorised person. The public evidence here does not establish which of those happened.
The question for any organisation receiving a sensitive records request is therefore separate from whether the sender address looks legitimate. Is the request associated with a valid legal process? Does the named official have the authority claimed? Do the case reference, agency contact and requested scope survive confirmation through a trusted channel that was not supplied inside the incoming email?
Those checks need to happen before export, not after a suspicious request is noticed. A reply to the same mailbox would only return to the address the impostor was already using. An independently obtained switchboard number, established secure portal or previously verified contact provides a different trust path. Organisations also need a process for emergency requests that is fast without treating urgency as a substitute for authentication.
This is the broader failure mode: a valid technical origin signal can be mistaken for valid legal and human authorisation. BlackTree recently examined a different trusted-channel failure involving Trezor customer emails. The channels and victims differ, but both incidents show why an authentic-looking delivery route cannot carry the whole decision.
What affected customers should do
Customers who received a Revolut notice should use the app or a bookmarked official site to review it and contact support. A follow-up email or call claiming to help with this incident could itself be an impersonation attempt. Do not send another identity document, one-time code or payment because an unsolicited message refers to the breach.
Monitor transactions and account notifications, and raise any unfamiliar activity with Revolut through its official support route. If a passport or driving-licence copy was included, follow the relevant issuing authority’s guidance before replacing it; replacing a document may not erase copies already disclosed. Keep a record of the notice and ask Revolut which categories of your information were included if its message is unclear.
For other banks and data custodians, the immediate audit is operational: locate the workflow for law-enforcement and regulator requests, establish who can approve disclosure, check whether verification is independent of the incoming channel, and log what was sent to whom and why. Limit each response to the records justified by the request. A fake government request becomes far more damaging when a single approval releases an entire customer history.
What is still unknown
The public account does not establish the number of affected customers, the jurisdiction, the agency involved, the mechanism by which the government-domain email was used or whether the recipient retained or redistributed the data. Claims that this was a breach of Revolut’s core systems, that funds were stolen or that particular customers were selected for their wealth are not confirmed by the company’s disclosure.
The verified lesson is narrower and more useful. Customer data can leave a financial institution without an attacker ever logging in to the bank. An apparently genuine official channel is not enough if the request, the human behind it and the scope of disclosure are not independently authenticated.
Sources
- TechCrunch, Revolut confirms customer data breach through fake government requests, published 12 September 2026 at 07:40 PDT (16:40 Europe/Madrid). It reviewed Revolut’s customer notice and obtained a company response.
- Reuters, Revolut confirms sensitive customer data breach, falling for fake government requests, published 12 September 2026. Syndicated copy timestamped 17:56 BST (18:56 Europe/Madrid).
- Revolut, contact information for official requests, undated public contact page, consulted 14 September 2026.


