Revolut Confirms Breach From a Faked Government Request
Security / news
Revolut Confirms Breach From a Faked Government Request
The company will not name the agency whose email domain was spoofed, citing a live police investigation into the impersonation.
A scammer who sent Revolut a data request from a real government agency's email domain received passports, driver's licenses and transaction histories for a limited number of customers, the fintech confirmed Sept. 12. Revolut said the request carried valid domain credentials and passed its internal checks before anyone realized it was fraudulent.
A Revolut spokesperson said the company "immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators" once it caught the deception, according to CoinDesk. The company said customer funds were not affected and that its own systems were not compromised.
What the fraudulent request actually pulled
The exposed data included customers' birth dates, home addresses, emails and phone numbers, plus copies of passports and driver's licenses, according to TechCrunch. CoinDesk reported the release may also have included verification selfies, IBANs, account statements and full transaction histories, including bitcoin activity. A pseudonymous on-chain investigator who flagged the leak, ZachXBT, said the breach appeared "limited in size" and suggested it targeted high-net-worth customers specifically.
That is a different failure mode than the CVE-driven breaches this desk usually covers, where a patch and a version number tell a reader exactly what to fix. Here, the vulnerability is a business process: Revolut apparently treats mail from a verified government domain as sufficient grounds to release identity documents, with no second channel required to confirm the request is real.
The company will not say which agency, or how many customers
Revolut has declined to identify the government agency whose domain was used, citing the ongoing police investigation, and has not disclosed how many customers were affected beyond calling the number limited. It said it contacted the affected individuals directly to offer support. It is not the company's first data-handling lapse: in 2023, criminals stole more than $20 million from Revolut by exploiting a mismatch between its U.S. and European payment systems, according to Haaretz.
The timing is awkward for a company in the middle of a licensing push. Haaretz reports Revolut is in the final stages of talks with the Bank of Israel over a banking license, with Uri Natan, the former chief executive of Israeli bank Leumi's digital banking arm Pepper, having led Revolut's Israeli operations for about 18 months. A breach involving passports and identity documents is not the story a fintech wants circulating while a national regulator is deciding whether to license it, and it is a reminder that social engineering aimed at trusted intermediaries works on financial institutions the same way it works on open-source maintainers: find the channel a target treats as automatically credible, then use it.
| Metric | Figure |
|---|---|
| Global customers | 80 million-plus |
| Countries operating as a bank | 30-plus |
| Private valuation (Nov. 2025) | $75 billion |
| Reported potential IPO valuation | up to $200 billion |
Revolut has not said how the spoofed domain passed its verification process, which is the question that matters more than the customer count for any company that gates sensitive disclosures on the sender's email domain rather than a signed, independently verifiable request. Until Revolut or the impersonated agency says more, that gap in the process, not the number of passports exposed, is the fact worth tracking.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.