Fake Govt Email Tricked Revolut Into Sharing KYC

Security Affairs · High sophistication
Last updated September 14, 2026

Revolut says it handed over sensitive customer identity and financial data after receiving what looked like a legitimate government information request. The email came from inside a real government agency’s email domain and passed authentication checks, so staff processed it before later discovering it was fraudulent. The exposed data included ID documents, verification selfies, account statements (including IBAN), and transaction history including Bitcoin.

How the attack worked

An attacker either created a rogue account within an official government agency's email domain or compromised an existing one, then used that account to submit what looked like a legitimate customer data request. Because the message carried valid domain authentication credentials, it passed automated authenticity checks and was processed under the reasonable belief that it was a genuine government request. Staff released a substantial data package in response, including identity documents, verification selfies, account statements with IBAN details, and full transaction history including Bitcoin.

Why it succeeded

The request exploited a gap between technical email authentication and actual authorization. Domain authentication confirms that a message originated from infrastructure tied to a domain, but it does not confirm that the specific sender or mailbox is authorized to make the request being made. Relying mainly on email authentication allowed an attacker with access to a government domain to bypass checks and obtain sensitive customer data without triggering a manual verification step before the data was sent.

What to watch for

  • Requests for a full KYC package (ID documents plus verification selfie) bundled with account statements and transaction history in a single ask.
  • Legal or government-style requests that arrive only by email with no independent verification channel offered or used.
  • Unusually broad or specific asks that suggest the requester already knows details about particular customers, which may indicate targeting of high-net-worth individuals.
  • Any data request where the only proof of legitimacy offered is a technically valid sending domain.

How to build resistance

Compliance, legal, AML/KYC operations, and fraud teams should treat valid domain authentication as necessary but not sufficient proof of a legitimate request. Before releasing customer data in response to a government or legal request, staff should independently verify the request through a known contact channel for the requesting agency, separate from the email that made the request. Unusually broad data requests, especially those combining identity documents, financial statements, and transaction histories, should be escalated for additional review rather than fulfilled on receipt. Building this verification step into standard procedure reduces the risk that a compromised or rogue account inside a trusted domain can be used to extract sensitive customer records.

Key findings

  • A fraudulent customer-data request was sent from an unauthorized mailbox that used a real government agency’s official email domain infrastructure.
  • The message “carried valid domain authentication credentials,” so it passed email authenticity checks and was processed as if it were a real government request.
  • Exposed data included identity/contact information, copies of passports/driver’s licenses, verification selfies, account statements (including IBAN), and full transaction histories including Bitcoin.
  • Revolut later discovered the fraud only after independently contacting the government agency to confirm the request, and the agency said it did not make the request.
  • A crypto security researcher assessed the operation appeared targeted at high-net-worth users.

Who’s being targeted

  • Commonly targeted roles: Compliance, Legal, AML/KYC Operations, Privacy/Data Protection, Fraud Operations, Customer Support (high-value customers), Security/Incident Response.
  • Affected industries: Fintech, Banking, Cryptocurrency/Blockchain services, Financial services compliance (KYC/AML).
  • Attack channels: email.
  • Impersonated: Government agency (official government email domain), Government agency investigator/authority.

Red flags to watch for

  • Request is made purely over email and relies on “valid domain authentication credentials” as proof, without an out-of-band verification step.
  • Unusual scope of data requested (e.g., full KYC package plus account statements/transaction history).
  • Sender mailbox is unauthorized even though it uses an official government domain (possible compromised/rogue account).
  • Highly sensitive combination of data requested (ID docs + selfie + IBAN/account statements + crypto transactions).
  • Request appears tailored toward wealthy individuals rather than a broad legitimate inquiry.
  • Verification happens only after fulfillment instead of before.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fraudulent request bypass Revolut's checks?

The email carried valid domain authentication credentials because it was sent from an unauthorized mailbox within a real government agency's official domain, so it passed authenticity checks and was processed as a legitimate request.

What customer data was exposed in this incident?

The exposed data included identity and contact details, copies of passports and driver's licenses, verification selfies, account statements including IBAN, and full transaction histories including Bitcoin.

How was the fraud discovered?

Revolut discovered the fraud only after independently contacting the government agency to verify the request, at which point the agency confirmed it had not made it.

Who appears to have been targeted in this attack?

A crypto security researcher assessed that the operation appeared to be targeted at high-net-worth users.

Read the video transcript

Revolut got a government email, checked the domain, it passed all the tests… and they still sent customer passports and Bitcoin history to a fraudster. The trick? The attacker used an unauthorized mailbox inside a real government email domain. It carried valid authentication, so staff believed it was a lawful request and handed over full KYC packs and transaction histories. Here’s the scary part: everything looked fine until Revolut later phoned the agency and heard, ‘We never sent that.’ By then, high‑net‑worth customers’ IDs, selfies, IBANs, and Bitcoin histories were already gone. Your move: if an email asks for a full KYC pack plus account or crypto history, stop. Independently call or portal‑message the supposed authority using a known number before you send a single file.

Similar attacks

Fake Government Email Tricked Revolut for Data

Fake Government Email Tricked Revolut for Data

Revolut confirmed that an attacker impersonated a government agency using an email address on that agency’s real domain to obtain sensitive customer records. Revolut says only a limited number of customers were affected and that customer funds and Revolut systems were not accessed.

September 14, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how…

July 29, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
ChatGPT-Enabled Scam Network Disrupted

ChatGPT-Enabled Scam Network Disrupted

A Cambodia-based scam network used ChatGPT to run multiple social-engineering schemes at once, including romance scams that pivoted into fake crypto/gold investments. The same operators also posed as online gambling reps offering fake winnings and as law enforcement demanding “fines,” using forged…

August 27, 2026
Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

The article describes real-world social engineering aimed at both consumers and financial firms, including phone-based attacks on hedge funds and a turnkey scam kit that impersonates Tesla to steal cryptocurrency. The kit uses a professional-looking fake presale website with urgency tactics…

August 12, 2026