Revolut Data Breach: Sensitive Customer Data Handed to Fake Government Agents
Revolut handed sensitive customer data to a hacker because the attacker managed to spoof the email domain of a government agency. An embarrassing data leak in which the information was served up on a plate to the hacker, who did not need to break into Revolut's systems. Here's what we know.
This story emerged overnight from Friday, September 11 to Saturday, September 12, 2026, when researcher ZachXBT (who specializes in crypto) posted on his Telegram group the notification received by Revolut customers. The story quickly gained traction, with initial statements from a Revolut spokesperson also being published by Jagmeet Singh of TechCrunch.
What happened? Here is the scenario. Revolut received information requests that appeared to come from a government agency. They were sent from the administration's real email domain, which allowed them to pass email authentication checks (DKIM and the like). Revolut's teams therefore handled these requests as if they were legitimate and lawful... before later realizing that they were not.
"Revolut recently identified a sophisticated external impersonation scam in which an unauthorized third party used the email address of a legitimate government agency domain to submit fraudulent information requests," the spokesperson told TechCrunch.
What makes this incident different from typical attacks involving a breach that leads to data theft is its nature: there was no intrusion, but rather a judgment error in how a request was handled.
Data Far More Sensitive Than a Simple Customer File
The data disclosed includes the identity and contact details of the customers involved (name, date of birth, postal address, email address, phone number), as well as copies of identity cards, passports, or driver's licenses. That's not all: in some cases, Revolut may also have disclosed verification selfies, account statements, and transaction histories.
In fact, according to the screenshot shared by ZachXBT and matching the notice sent to customers, there would also be other details such as occupation. The notice also mentions banking information: the IBAN, account status, opening date, and Bitcoin wallet references, all tied to the full history.

That means Revolut virtually handed over everything it had in its possession (with the exception of biometric data), believing it was dealing with a government agency.
The Unknowns
One question remains unanswered, or rather several gray areas remain.
First of all: how many people were affected? And more importantly, I wonder how the request was worded: did the hacker name specific people or specify criteria in the request? Wealthy customers, for example. One can imagine the request was targeted to serve the attacker's interests.
For its part, Revolut refers to a limited number of customers who were contacted directly, without saying how many. However, Revolut has not named the agency whose email domain was spoofed, and it is not specified whether this incident was limited to a single country.
Another question concerns the email domain itself. How did the hacker gain access: a compromised employee mailbox, an account created with that domain, or some other simpler method? The ongoing investigation should provide more details on this point.

