
Revolut discloses customer data to scammers using authenticated government email
British fintech Revolut handed over customer identity documents, verification selfies, and transaction records after falling for fraudulent requests sent from a legitimate government agency email domain.
Fraudulent government requests
British financial technology company Revolut confirmed on 12 September 2026 that sensitive customer data was disclosed to an unauthorized third party following an impersonation scam. The attackers submitted fraudulent requests for information using a genuine email domain belonging to a legitimate government agency. The messages carried valid technical domain authentication, leading company personnel to treat the inquiries as lawful statutory disclosure orders and transmit the requested files.
A company spokesperson detailed the nature of the attack:
Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.
Scope and compromised records
The compromised records encompassed customer identity and contact information, including full names, dates of birth, postal addresses, email addresses, and phone numbers. The transmitted packages also contained copies of official identity documents, such as driver's licenses and passports. Affected customers received notification emails indicating that account statements, verification selfies, transaction histories, and international bank account numbers were also potentially exposed during the incident.
Independent cryptocurrency investigator ZachXBT reported on Friday evening that the scam appeared specifically tailored to target high-net-worth individuals holding accounts with the digital bank. Revolut stated that a limited number of clients were affected and that all impacted individuals were contacted directly. Citing ongoing investigations and confidentiality requirements, the company declined to disclose the exact count of affected users, the identity of the spoofed government agency, or the specific national jurisdictions involved.
- US OCC grants conditional approval for Revolut to establish a national bank
- Security researcher ZachXBT publishes details of notification emails sent to affected clients
- Revolut confirms unauthorized data disclosure following spoofed government request
- Revolut projects operational launch of its United States banking unit
Containment and official notifications
Revolut identified the fraudulent nature of the inquiry only after contacting officials at the relevant agency, after which internal security teams blocked the sender's address. The London-based company emphasized that its core banking infrastructure, administrative systems, and customer balances remained untouched throughout the security breach.
A company spokesperson outlined the subsequent disclosures to state authorities:
As soon as we detected the incident, we immediately blocked the address and alerted the relevant government agency, as well as law enforcement, data protection authorities, and financial regulators.
Market position and expansion
Founded in 2015 as a branchless digital lender, Revolut maintains a global client base of over 80 million users across more than 30 countries. France represents approximately 10% of total users, while Romania accounts for between 4.5 million and 5 million customers, forming the bank's third-largest market after the United Kingdom and France. The company has expanded operations into India, Mexico, and the United Arab Emirates.
- November private valuation
- 75 $B
- Target IPO valuation
- 200 $B
Earlier in September 2026, the United States Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a national bank, with an operational launch expected in the first half of 2027. The breach occurred while the company evaluated a potential initial public offering aiming for a $200 billion valuation, compared to its $75 billion private valuation recorded in November.


