Revolut Tricked by Fake “Emergency” Data Requests

The Record · High sophistication
Last updated September 15, 2026

Revolut confirmed it disclosed sensitive customer information after fraudsters sent “emergency” information requests from a legitimate government email domain. The attackers appear to have targeted high-net-worth customers, including people involved in crypto, and attempted to extort Revolut to prevent broader data release.

How the attack worked

Fraudsters submitted what looked like a legitimate emergency data request (EDI) using a real government agency email domain. The pretext relied on urgency: the request demanded immediate disclosure of customer information, framing the situation as time-critical to discourage standard verification steps. Because the sender's domain appeared authentic, the request bypassed normal scrutiny that a compliance or legal team might apply to an unfamiliar sender.

According to reporting, the attackers appeared to focus on high-net-worth customers, including individuals involved in crypto asset businesses. The data obtained reportedly included identity documents, verification selfies, bank statements, IBANs, withdrawal records, and transaction history including Bitcoin activity, a scope far broader than a routine, narrowly-defined law enforcement request would typically require.

Why it succeeded

The core failure point was trust placed in the sending domain rather than the legitimacy of the request itself. A legitimate-looking government email address created a false sense of assurance, even though the underlying access may have been unauthorised or compromised. This mirrors a pattern seen in prior incidents where criminals used compromised law enforcement accounts to submit forged emergency data requests to major tech companies, exploiting the same urgency and domain-trust dynamic.

The emergency framing itself is a well-known social engineering lever: it pressures staff to act quickly and skip escalation or independent verification, especially when the requester claims lives or investigations are at stake.

What to watch for

  • Requests labeled "emergency," "urgent," or "immediate disclosure required" for customer records
  • Broad requests for complete identity and financial data rather than narrowly scoped information
  • Government-domain senders requesting expedited handling outside normal legal channels
  • Any request that discourages a callback or independent verification step

How to build resistance

Organizations handling sensitive customer data should treat every emergency data request as high-risk by default. Practical steps include:

  • Requiring independent verification (a callback to a known, previously validated contact number) before releasing any data under an emergency request
  • Escalating any request for broad identity or financial records to privacy and legal leadership rather than allowing frontline teams to respond directly
  • Recognizing that a legitimate-looking sending domain does not guarantee the request itself is authorized, since accounts can be compromised or misused
  • Maintaining a predefined incident playbook for extortion attempts following data exposure, covering communication with regulators and law enforcement

These measures target the specific mechanism this incident relied on: urgency plus domain trust overriding standard verification. Building friction into emergency request handling, without slowing genuinely legitimate law enforcement cooperation, is the practical defense against this technique.

Key findings

  • Fraudsters used a legitimate government agency email domain to submit fraudulent “emergency” requests for customer information.
  • The perpetrators appeared to focus on high-net-worth individuals, including those involved in crypto asset businesses.
  • Exposed data (per customer notices shared by impacted individuals) included identity documents and financial activity such as bank statements, IBANs, withdrawal records, and transaction history including Bitcoin activity.
  • Attackers allegedly attempted to extort Revolut to prevent customer data from being released.
  • This mirrors prior tactics where criminals used compromised law-enforcement accounts and forged emergency data requests to obtain data from major tech firms.

Who’s being targeted

  • Commonly targeted roles: Legal, Compliance, Privacy/Data Protection, Customer Support, Fraud/Trust & Safety, Security Operations, Executive leadership (incident decision-makers).
  • Affected industries: Financial services / fintech, Cryptocurrency / digital assets.
  • Attack channels: email.
  • Impersonated: Government agency (using a legitimate government domain email account).

Red flags to watch for

  • Request relies on urgency/emergency framing to bypass normal verification steps
  • Sender uses a legitimate-looking government domain but the request is unauthorised
  • Request seeks unusually broad/complete customer data (IDs, selfies, bank statements, transaction history)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is an emergency data request attack?

It is when attackers impersonate a government agency or law enforcement using urgency framing to convince a company to bypass normal verification and release customer data immediately.

How did fraudsters access a legitimate government email domain?

The JSON does not specify how the domain was obtained, only that an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information.

What kind of data was exposed in this incident?

Exposed data reportedly included birth dates, addresses, phone numbers, passport and driver's license copies, verification selfies, bank statements, IBANs, withdrawal records, and transaction histories including Bitcoin activity.

Who was targeted in this scheme?

The perpetrators appeared to focus on high-net-worth individuals, including those involved in crypto asset businesses.

Read the video transcript

Revolut leaked customer data because of one email that looked like it came from a real government address. Fraudsters used a legitimate government agency email to send fake “emergency” data requests, then tried to extort Revolut after getting IDs, bank statements, even Bitcoin transaction history. Here’s the trap: the domain looked real, the tone was urgent, and the request asked for everything at once, perfect recipe to skip normal checks and just send the data. If you ever get an “emergency” request for customer data, even from a real-looking government email, stop and call back using our approved contacts before you send anything.

Similar attacks

Revolut Fooled by Fake Government Data Requests

Revolut Fooled by Fake Government Data Requests

Revolut confirmed it shared sensitive customer information with an unauthorized party after accepting fraudulent “government” information requests sent from an email address on a legitimate government domain. The company says this was an external impersonation scam (not a system hack) and that…

September 14, 2026
Fake Govt Email Tricked Revolut Into Sharing KYC

Fake Govt Email Tricked Revolut Into Sharing KYC

Revolut says it handed over sensitive customer identity and financial data after receiving what looked like a legitimate government information request. The email came from inside a real government agency’s email domain and passed authentication checks, so staff processed it before later…

September 12, 2026
Instagram Copyright Strikes Used for Ransom

Instagram Copyright Strikes Used for Ransom

Scammers are filing fake copyright complaints to get Instagram accounts temporarily suspended, then demanding money to “withdraw” the complaint and restore access. Victims are pushed to communicate off-platform (for example, on Telegram) and asked to pay in cryptocurrency, yet even paying doesn’t…

September 10, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026