Revolut Fooled by Fake Government Data Requests

About DFIR · High sophistication
Last updated September 15, 2026

Revolut says it disclosed sensitive customer information after receiving fraudulent information requests that appeared to come from a real government agency email domain. The company framed it as a sophisticated impersonation scam, not a technical break-in, showing how “legitimate-looking” requests can still be malicious when they ask for customer data.

Key findings

  • Revolut disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests.
  • The requests were sent from “a legitimate government agency’s email domain,” making the outreach look authentic.
  • Revolut characterized the incident as “a sophisticated impersonation scam rather than a system intrusion.”
  • Exposed data included identity and contact details, dates of birth, addresses, phone numbers, and copies of identity documents; in some cases it included verification selfies, statements, and transaction histories.
  • The incident highlights that authenticated-looking government-domain emails still require strict verification before releasing customer data.

Who’s being targeted

  • Commonly targeted roles: Compliance, Legal, Customer Support, Trust & Safety, Privacy/Data Protection, Fraud/Risk Operations.
  • Affected industries: Financial services / Fintech.
  • Attack channels: email.
  • Impersonated: Government agency (using a legitimate government email domain).

Awareness takeaways

  • Do not treat a recognizable sender domain (even a government domain) as proof a request is legitimate, verify requests through an independent, documented process before sharing customer data.
  • Train teams who handle sensitive disclosures (Compliance/Legal/Support) to recognize impersonation-based data requests as a breach risk, even when no systems are ‘hacked.’
  • Apply extra scrutiny and escalation for requests seeking high-risk identity artifacts (passports, driver’s licenses, selfies) and financial records (statements/transactions).

Red flags to watch for

  • The request relies on the sender’s domain reputation rather than a verified case number/process.
  • High-sensitivity data requested (IDs, selfies, statements) without strong, independent verification.
  • Unusual urgency or deviations from standard lawful-request workflow (e.g., submitted by email alone).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Revolut handed over customer data to a fraudster… and the email came from a real government domain. The message said, 'We are requesting sensitive customer information as part of an official government information request.' Because it looked authentic, Revolut sent IDs, selfies, statements, even transaction histories, to an unauthorized third party. Here’s the trap: the attacker didn’t hack Revolut’s systems. They exploited trust in a real government email domain. Even properly authenticated, legitimate-looking correspondence can be malicious when it asks for customer data. If an email asks for IDs, selfies, or statements, even from a government domain, stop and follow our official lawful-request process. One rule: no process, no data.

Similar attacks

Revolut Fooled by Fake Government Data Requests

Revolut Fooled by Fake Government Data Requests

Revolut confirmed it shared sensitive customer information with an unauthorized party after accepting fraudulent “government” information requests sent from an email address on a legitimate government domain. The company says this was an external impersonation scam (not a system hack) and that…

September 14, 2026
Revolut Tricked by Fake Government Email

Revolut Tricked by Fake Government Email

Revolut disclosed it was deceived into sharing highly sensitive customer data after receiving fraudulent information requests that appeared to come from a legitimate government email domain. The attacker’s email passed domain authentication, making it harder to detect, and the shared data may…

September 14, 2026
Fake Government Email Tricked Revolut for Data

Fake Government Email Tricked Revolut for Data

Revolut confirmed that an attacker impersonated a government agency using an email address on that agency’s real domain to obtain sensitive customer records. Revolut says only a limited number of customers were affected and that customer funds and Revolut systems were not accessed.

September 14, 2026
Fake Govt Email Tricked Revolut Into Sharing KYC

Fake Govt Email Tricked Revolut Into Sharing KYC

Revolut says it handed over sensitive customer identity and financial data after receiving what looked like a legitimate government information request. The email came from inside a real government agency’s email domain and passed authentication checks, so staff processed it before later…

September 12, 2026
Revolut Hit by Govt-Agency Email Impersonation

Revolut Hit by Govt-Agency Email Impersonation

Revolut says a third party posing as a government agency tricked the company into disclosing some customers’ personal and financial data. The attacker used an email address on a legitimate government agency domain, causing the request to be treated as a real legal inquiry. Revolut says customer…

September 14, 2026
Revolut Tricked by Fake “Emergency” Data Requests

Revolut Tricked by Fake “Emergency” Data Requests

Revolut confirmed it disclosed sensitive customer information after fraudsters sent “emergency” information requests from a legitimate government email domain. The attackers appear to have targeted high-net-worth customers, including people involved in crypto, and attempted to extort Revolut to…

September 14, 2026