Revolut Fooled by Govt Impersonation Email

Help Net Security · Medium sophistication
Last updated September 21, 2026

A person posing as a government agency used an email address on that agency’s real domain to obtain sensitive customer records from Revolut. The same weekly roundup also describes a fake antivirus renewal web page impersonating Avast, telling victims their subscription renewed for €129.99 and prompting them to act.

How the attack worked

A person impersonating a government agency used an email address on that agency's real domain to request sensitive customer records. Because the email came from an authentic domain, it carried the appearance of legitimacy, and Revolut confirmed the incident. This case illustrates how domain-level authenticity can be misused: owning or accessing a real government email address is enough to make a request look credible, even when the actual sender has no authorization to make it.

Why it succeeded

The request relied on implied authority rather than a verified process. Customer support, compliance, and fraud teams are trained to respond to legitimate government inquiries, and an email from a real agency domain short-circuits the usual skepticism. Without a separate verification step, such as calling a published agency contact or checking an internal escalation list, a convincing domain and an authoritative tone can be enough to move sensitive data.

A related example from the same period shows a different but connected pattern: a fake Avast renewal page told visitors their subscription had renewed for €129.99 and would renew again in February. Researchers noted the page was more polished than typical scam sites, suggesting AI tools are helping less skilled scammers build convincing fakes. Both cases show that visual or domain-level polish is not a reliable signal of legitimacy.

What to watch for

  • Requests for sensitive customer data based solely on an email, without a secondary verification step
  • Reliance on sender domain trust instead of a documented, verified request process
  • Urgency or authority-based pressure from an external party asking for records or payment action
  • Unexpected billing or renewal notices that push a quick response
  • Pages or messages that look unusually professional; polish alone does not confirm authenticity

How to build resistance

Organizations handling customer data, especially in banking and fintech, should require independent verification for any external request involving sensitive records, regardless of how authoritative the sender domain appears. This means confirming requests through officially published contact channels rather than replying to the original email.

Employees across all teams should also be trained to treat unexpected renewal or billing messages with the same skepticism, using vendor contact information they look up themselves rather than links or numbers provided in the message. Building this habit into standard workflows, rather than relying on individual judgment in the moment, reduces the chance that a well-crafted impersonation attempt succeeds. As scam pages become more polished with the help of AI tools, verification processes matter more than visual trust signals.

Key findings

  • Revolut said a party impersonating a government agency used an email address on that agency’s domain to obtain sensitive customer records.
  • A scam web page impersonating Avast told users their Avast Premium Security subscription had renewed for €129.99 and would renew again in February.
  • Attackers also abused a trusted online presence by compromising the verified official HBO Max Reddit account and using it for a malvertising campaign (ClickFix).

Who’s being targeted

  • Commonly targeted roles: Customer Support, Compliance, Fraud/Investigations, Finance, All Employees, IT Helpdesk.
  • Affected industries: Banking/Fintech, Consumer/retail banking customers, Media/Entertainment (social account hijack context).
  • Attack channels: email, website.
  • Impersonated: A government agency (using that agency’s real email domain), Avast.

Red flags to watch for

  • Request for sensitive customer data based solely on an email
  • Relies on sender domain trust rather than a verified request process
  • Unusual urgency or authority-based pressure from an external party
  • Unexpected renewal charge and pressure to act
  • Brand impersonation (Avast) on an untrusted page
  • High-pressure billing language designed to trigger panic clicks/calls
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers get Revolut to share customer data?

Someone impersonating a government agency used an email address on that agency's actual domain to request and obtain sensitive customer records from Revolut.

Why did the sender's domain not guarantee legitimacy?

Using a real domain does not prove the sender is authorized to act for that agency, since domain trust alone was relied on instead of a verified request process.

What other impersonation tactic was seen in the same period?

A fake Avast renewal page told visitors their subscription had renewed for €129.99 and would renew again in February, pressuring them to act quickly.

What should employees do before responding to authority-based requests?

Verify the request through an official, independently looked-up channel rather than replying directly to the email or trusting the sender domain alone.

Read the video transcript

Someone used a real government email domain to trick Revolut into handing over sensitive customer records. The email looked official, came from that agency’s real domain, and asked for customer records. Revolut confirmed on September twelfth that they sent data based only on that email. Same playbook on the web: a polished fake Avast page says your Avast Premium Security just renewed for €129.99, covers five devices, and will renew again in February, pushing you to click or call fast. Here’s the move: if any email or web page asks for data or money, ignore the link and start your own contact, use our official process or the vendor’s site you look up yourself.

Similar attacks

Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
Fake Fortnite Rewards Lure Epic Login Theft

Fake Fortnite Rewards Lure Epic Login Theft

Scammers are setting up fake Fortnite “rewards,” “locker value,” and “competition” websites that funnel players to a fake Epic Games login page. The sites trick people into signing in so attackers can steal Epic usernames and passwords, then take over accounts for resale, fraud, or further scams. A…

July 31, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Fake Avast Renewal Page Lures Victims Into Calls

Fake Avast Renewal Page Lures Victims Into Calls

Researchers found a realistic-looking fake Avast renewal page that claims a subscription renewed for €129.99 and pushes victims to “cancel” by entering their name, email, and mobile number. The charge is fake, and the real goal is to collect contact details so scammers can follow up with a phone…

September 16, 2026