Revolut Fooled by Fake Government Data Requests

Malwarebytes · Medium sophistication
Last updated September 14, 2026

Revolut confirmed it shared sensitive customer information with an unauthorized party after accepting fraudulent “government” information requests sent from an email address on a legitimate government domain. The company says this was an external impersonation scam (not a system hack) and that customer funds were not affected, but exposed data could enable follow-on identity fraud and scams.

Key findings

  • Revolut disclosed sensitive customer records to an unauthorized party after accepting fraudulent information requests.
  • The requests were sent “from an email address on a legitimate government agency domain,” leveraging trust in official domains.
  • Revolut described the incident as “an external impersonation scam, not an intrusion into its systems,” and said “customer funds were not affected.”
  • Exposed data types included identity/contact details, copies of IDs (passport/driver’s license), verification selfies, and account statements/transaction histories.
  • Revolut says only a “limited” or “very limited” number of customers were affected and those customers are being contacted directly.

Who’s being targeted

  • Commonly targeted roles: Legal, Compliance, Privacy/Data Protection, Customer Support/Operations, Fraud/Financial Crime team.
  • Affected industries: Financial services / digital banking.
  • Attack channels: email.
  • Impersonated: Government agency (unspecified).

Awareness takeaways

  • Treat unexpected ‘official’ requests for sensitive data as suspicious and verify using trusted, independent channels before responding.
  • Have a clear process for responding to law-enforcement/government data requests, including verification steps and escalation to Legal/Privacy.
  • Prepare customers and front-line teams for follow-on scams after data exposure (account ‘security’ messages, reverse-transfer scams, document ‘replacement’ requests).

Red flags to watch for

  • Unusual or unexpected request for sensitive customer records via email, even if the sender domain appears official
  • Pressure to comply without secondary verification or a known case/reference number
  • Request scope includes high-risk documents (IDs, selfies, transaction history) beyond what is necessary
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Revolut just handed real customer data to a scammer… from what looked like a real government email. The scammer emailed from a legitimate government domain, asked for IDs, selfies, and transaction history, and Revolut sent it, no system hack, just trust in the email. Here’s the trap: the email feels urgent and official, but it’s unexpected, has no clear case number, and demands way more data than a normal request. If you get an ‘official’ email asking for customer records, stop. Don’t reply from the email, call or message the agency using our approved contact list and verify first.

Similar attacks

Fake Govt Email Tricked Revolut Into Sharing KYC

Fake Govt Email Tricked Revolut Into Sharing KYC

Revolut says it handed over sensitive customer identity and financial data after receiving what looked like a legitimate government information request. The email came from inside a real government agency’s email domain and passed authentication checks, so staff processed it before later…

September 12, 2026
Revolut Tricked by Fake “Emergency” Data Requests

Revolut Tricked by Fake “Emergency” Data Requests

Revolut confirmed it disclosed sensitive customer information after fraudsters sent “emergency” information requests from a legitimate government email domain. The attackers appear to have targeted high-net-worth customers, including people involved in crypto, and attempted to extort Revolut to…

September 14, 2026
Revolut Tricked by Fake Government Email Requests

Revolut Tricked by Fake Government Email Requests

Revolut confirmed a breach after an attacker impersonated a government agency and sent fraudulent data requests from what appeared to be a legitimate government email domain. Employees processed the requests as normal legal-compliance work, leading to exposure of sensitive customer identity and…

September 14, 2026
Revolut Tricked by Fake Government Email

Revolut Tricked by Fake Government Email

Revolut disclosed it was deceived into sharing highly sensitive customer data after receiving fraudulent information requests that appeared to come from a legitimate government email domain. The attacker’s email passed domain authentication, making it harder to detect, and the shared data may…

September 14, 2026
Fake Government Email Tricked Revolut for Data

Fake Government Email Tricked Revolut for Data

Revolut confirmed that an attacker impersonated a government agency using an email address on that agency’s real domain to obtain sensitive customer records. Revolut says only a limited number of customers were affected and that customer funds and Revolut systems were not accessed.

September 14, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026