On September 12, 2026, British fintech Revolut confirmed that an unauthorised third party obtained sensitive customer data after fraudulent information requests sent from a legitimate government agency email domain passed the company's authentication checks and were fulfilled. The incident, which Revolut described as a sophisticated external impersonation scam, exposed identity documents, contact details, and financial records for a limited number of customers. The company said its systems and customer funds were unaffected.
Revolut serves more than 80 million customers globally and operates as a bank in more than 30 countries. It is reportedly weighing a public listing that could value it at as much as $200 billion, up from a $75 billion private valuation in November 2025. Earlier in September 2026, the US Office of the Comptroller of the Currency granted conditional approval for Revolut to set up a national bank, expected to launch in the first half of 2027. The company is also in the final stages of talks with the Bank of Israel to obtain a licence to operate as a light bank.
The breach came to light after a customer notification began circulating on September 11, 2026. Affected customers were told on Friday, September 11, that their information had been disclosed. Former Mt. Gox chief executive Mark Karpelès posted excerpts of the notice at 07:06 UTC on September 12 after receiving it himself at 21:59 UTC on September 11. Crypto security researcher ZachXBT flagged the case and later assessed that the incident appeared targeted at high-net-worth users.
According to the notification, the fraudulent request came from an unauthorised email account sent directly using the official government agency's email domain. The message carried valid domain authentication credentials, meaning it passed SPF, DKIM and DMARC checks. Revolut fulfilled the request under the reasonable belief that it was an authentic government agency request. The company only discovered the fraud afterwards by contacting the agency, which confirmed it had not made the request. This was not a technical breach: no systems were compromised, no malware was used, and Revolut's servers were not accessed by an outsider.
Key Facts
TechCrunch reported on September 12 that Revolut disclosed sensitive customer information to an unauthorised third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included birth date, postal and email addresses, phone numbers, passports, and driver's licences. It may have also included verification selfies, account statements, and transaction histories. A spokesperson confirmed a limited number of customers were impacted and said the company contacted them directly. Revolut did not disclose the exact number, the market affected, or the government agency involved.
SecurityAffairs reported on September 12 that the notification began circulating on September 11, 2026, and stated the communication carried valid domain authentication credentials. The notice listed four data categories: identity details (full name, date of birth, occupation); contact details (postal address, email, telephone number); document and verification data (passport or driver's licence and facial verification selfie, with no biometric facial telemetry compromised); and financial data (account statements including IBAN, account status, opening date, wallet reference number, withdrawal records, and full transaction history including Bitcoin). The attacker either created a rogue account within the agency's domain or compromised an existing one.
Cointelegraph reported on September 13 that Revolut released sensitive data including passports, verification selfies, and full transaction histories after a fraudulent request. A spokesperson said: 'Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.' Upon detection, Revolut blocked the address, alerted the government agency, enforcement agencies, and financial regulators. The spokesperson added that systems and customer funds were unaffected and that the limited number of impacted individuals had been contacted directly.
Reuters reported on September 13 that Revolut confirmed the disclosure to an unauthorised third party. The spokesperson said: 'Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,' without disclosing the number affected. The compromised data included birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver's licences.
Crypto Times reported on September 12 that Revolut informed a subset of customers that personal and financial records, including Bitcoin transaction histories, were sent to an unauthorised third party after treating a government-styled request as genuine. The notice described the request as originating from a mailbox within an official government agency's domain infrastructure. The story widened publicly on September 12 when Mark Karpelès posted excerpts at 07:06 UTC.
Analysis
The most striking element is not the volume of data exposed but the method used. The attacker did not break into Revolut's systems, deploy malware, or exploit a vulnerability. Instead, they abused a trusted communication channel: a legitimate government agency's email domain. By sending requests from a mailbox inside that domain, the attacker bypassed SPF, DKIM, and DMARC checks. What this really means is that the security perimeter around sensitive data is only as strong as the weakest link in a chain of trust, and in this case the chain was a government agency's email infrastructure.
The incident also highlights a growing trend in which attackers target human and process layers rather than the technical layer. Revolut's systems performed as expected: they authenticated the email as coming from a legitimate source. The failure was in the verification process that followed, which relied on the assumption that a message from a government domain is inherently trustworthy. The attacker either created a rogue account within the agency's domain or compromised an existing one.
The targeting of high-net-worth users, as assessed by ZachXBT, adds concern. If the incident was limited to a small number of wealthy individuals, it points to a calculated effort to harvest valuable personal and financial data, including Bitcoin transaction histories. Such data can be used for identity theft, extortion, or targeted phishing. The bigger picture here is that KYC data, which financial institutions are required to collect, has become a high-value target for criminals, and the mechanisms meant to protect it can be turned against the very customers they are meant to serve.
For Revolut, the timing could hardly be worse. The company is in the final stages of talks with the Bank of Israel for a banking licence, has received conditional approval from the US Office of the Comptroller of the Currency to set up a national bank, and is reportedly weighing a public listing that could value it at up to $200 billion.
Why It Matters
This breach matters because it exposes a systemic vulnerability that extends far beyond Revolut. Financial institutions routinely receive information requests from government agencies and must balance compliance against the risk of data disclosure. The fact that a fraudulent request from a legitimate government domain passed authentication checks at a major fintech suggests that other companies could be similarly vulnerable. Regulators may now scrutinise how institutions verify the authenticity of such requests, potentially leading to requirements for out-of-band verification.
It also raises questions about the mandatory collection of KYC data. As one user, Marc Zeller, wrote on X: 'Sharp reminder that KYC hasn't produced meaningful upside and has put many in harm's way.' While KYC is a critical tool against money laundering and terrorist financing, the incident illustrates the risks of centralising sensitive personal information. Customers have little choice but to provide this data, and when it is compromised, they bear the consequences. This could fuel calls for better data minimisation, stronger encryption, and more robust identity verification processes.
The breach also underscores the importance of email security for all organisations, including government agencies. If an agency's domain can be used to send fraudulent requests without detection, it undermines trust in official communications. The attacker's ability to pass SPF, DKIM, and DMARC checks indicates that either the agency's email infrastructure was compromised or an insider threat was involved.
Next Up
Revolut has alerted the relevant government agency, law enforcement, data protection, and financial regulators. Investigations are likely underway to determine the identity of the attacker and the full extent of the data exposed. The company has not disclosed the exact number of affected customers, the country or name of the impersonated agency, or the date the files left the firm.
Meanwhile, Revolut's planned public listing and its applications for banking licences in the US and Israel will be closely watched. Regulators may seek assurances that the company's internal controls are adequate before granting further approvals. Customers, particularly high-net-worth individuals, may demand more transparency about how their data is protected. The incident could also accelerate industry-wide efforts to develop more secure methods for sharing customer information with government agencies, such as requiring digitally signed requests or verification through multiple channels.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.