Revolut data breach: a real government email used to commit fraud
A fraudster used a genuine government email domain to extract passports, verification selfies and transaction histories from Revolut customers. No system was hacked and no money moved. The weak point was how the fintech vets official-looking requests for data, and the fallout has since widened into an extortion campaign.
The Revolut data breach disclosed on 12 September turned on a simple deception: a fraudster used a genuine government email domain to prise passport copies, verification selfies and full transaction histories out of the London fintech. Revolut confirmed the requests arrived from a real government agency domain and carried valid authentication, so staff treated them as a lawful demand and complied. It later judged the requests fraudulent, blocked the address, alerted the agency and regulators, and began notifying affected customers.
What did the attacker obtain?
According to the customer notice, the exposed material may have included each person's full name, date of birth and occupation; home address, email and phone number; copies of a passport and/or driving licence together with the verification selfie taken at onboarding; and account statements, IBAN, withdrawal records and full transaction history, including Bitcoin activity.
Revolut says biometric facial data was not disclosed, and that passwords, card PINs and crypto private keys did not leave. No customer funds have been reported missing. The company has described the number of affected customers only as "limited" and has not named the market or the government agency involved while an investigation is live.
Were Revolut's systems breached?
No. Revolut's core banking systems held and no customer money moved. What failed was the process for vetting official-looking requests for customer data. Reporting indicates the fraudulent messages carried valid SPF, DKIM and DMARC authentication results, and Revolut's process treated that domain authentication as evidence that the request itself was lawful. Most large leaks begin with stolen credentials or an exposed database. This one began with a mailbox that cleared the checks a compliance team is trained to trust: an official domain, valid authentication and the shape of a lawful demand.
The disclosed file is the problem. A passport, a home address and a full payment history are enough to assemble a targeted fraud pack. Where Bitcoin activity sits on the same statement, a recipient can attempt to tie a legal identity to an on-chain trail, a risk that ordinary card fraud does not carry.
How does a fraudulent government request get past a compliance team?
This attack has a long paper trail. Security researcher Brian Krebs documented criminals spoofing government legal requests as far back as 2022, and the tactic was used by the Lapsus$ group. The FBI warned US firms in Private Industry Notification 20241104-001, issued on 4 November 2024, that compromised government email accounts from more than two dozen countries were being sold on criminal forums specifically to submit fraudulent requests for customer data. In one earlier case, PayPal received a bogus cross-border legal request and declined it.
The mechanics are consistent: a request that looks legitimate because the domain genuinely belongs to an authority, sent to the channel a regulated firm uses to answer law enforcement. The defence is procedural rather than technical, a callback to a verified contact or a second sign-off before identity documents leave the building, and it is a control many firms have not hardened.
How has the incident escalated since?
The disclosure has since turned into an active extortion campaign. The attackers have started posting sample records on Telegram and, according to reporting corroborated across several outlets, warned that they will keep releasing data daily until Revolut pays. They have also accused the company of negligence and of allowing customer data to reach jurisdictions beyond its own, and threatened to publish internal information about how Revolut operates.
The financial demand should be treated as an unverified attacker claim. Some outlets have reported a figure of 10,000 bitcoin, worth roughly $780m at the time, but that figure has not been confirmed by Revolut and is not consistently corroborated. Revolut has not said whether it will pay. Samples said to contain the records of high-profile, high-net-worth individuals have circulated online, consistent with on-chain investigator ZachXBT's early reading that the operation appeared aimed at wealthy account holders. Their authenticity is unverified, and the naming of an individual in a sample does not confirm that person was affected, as threat actors routinely mix genuine records with fabricated or outdated material.
Why this matters to FinanceX readers
Revolut serves more than 80 million customers across more than 30 countries, won preliminary conditional approval from the US Office of the Comptroller of the Currency on 3 September to form Revolut Bank US, National Association, and is reported to be weighing a listing valued at up to $200bn, against a $75bn private valuation in November 2025. A national charter places its US business under direct federal supervision for the first time, with FDIC and Federal Reserve sign-off still to come before a planned launch in the first half of 2027. A live question over how customer identity data is protected, now compounded by a public extortion campaign, is an unhelpful backdrop to that process.
For every regulated firm, not only Revolut, the lesson is that identity data is now the target and the legal-request channel is one of the softer routes to it. The disclosure landed two days after ID verification vendor IDScan confirmed a breach exposing more than 150 million driving licences. The know-your-customer packs that firms are required to collect have become concentrated stores of exactly the material fraudsters need. The risk committee questions are practical: how many files went out, which legal entity and agency domain were involved, and whether a verification step now sits between an inbound government request and any release of customer records.



