Revolut Tricked by Fake Government Email

IT Pro Security · High sophistication
Last updated September 14, 2026

Revolut disclosed it was deceived into sharing highly sensitive customer data after receiving fraudulent information requests that appeared to come from a legitimate government email domain. The attacker’s email passed domain authentication, making it harder to detect, and the shared data may enable follow-on scams and identity fraud.

Key findings

  • Revolut was fooled into disclosing customer information due to fraudulent requests that came from a legitimate government email domain.
  • Exposed data reportedly included identity documents (passport/driver’s license) and facial verification images, plus bank statements and full transaction history (including Bitcoin).
  • The attacker’s email had valid domain-authentication credentials, reducing the chance it would be flagged as suspicious.
  • Revolut stated internal systems and customer funds were not affected; it blocked the unauthorized email source and notified authorities.
  • A researcher suggested the incident may have targeted high-net-worth individuals.

Who’s being targeted

  • Commonly targeted roles: Compliance, Legal, Customer Support, Fraud Operations, Privacy / Data Protection, Security Operations.
  • Affected industries: Digital banking, Retail banking, Cryptocurrency / digital assets.
  • Attack channels: email.
  • Impersonated: Unnamed official government authority (via legitimate government email domain).

Awareness takeaways

  • Treat sensitive data requests as high-risk even when the sender’s email domain looks legitimate; verify through a separate, known-good channel.
  • Train compliance/legal/support teams to spot “overbroad” requests (identity documents, facial images, full transaction history) as a major warning sign.
  • Don’t rely on email authentication alone as proof of legitimacy; attackers may obtain or create accounts inside trusted domains.

Red flags to watch for

  • Request asks for unusually broad/highly sensitive data (ID documents + facial verification + full transaction history).
  • Request relies only on email and pressures staff to treat a “legitimate address” as sufficient proof.
  • No clear department name, jurisdiction, or case reference that can be independently verified.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Revolut shared passport scans and full transaction histories because of one email that looked like it came from a real government address. The message said, “This is an official request from our department,” and asked them to reply with identity documents, facial verification images, bank statements, and full Bitcoin transaction history. Here’s the trap: the email really did come from inside a government domain, so filters trusted it. But there was no clear department name, no case reference, and the scope was way too broad for a normal request. If any email asks for ID documents, facial images, or full transaction history, pause and verify it through a known-good channel, like calling the official number on file, before you send a single file.

Similar attacks

Revolut Hit by Govt-Agency Email Impersonation

Revolut Hit by Govt-Agency Email Impersonation

Revolut says a third party posing as a government agency tricked the company into disclosing some customers’ personal and financial data. The attacker used an email address on a legitimate government agency domain, causing the request to be treated as a real legal inquiry. Revolut says customer…

September 14, 2026
Revolut Tricked by Fake Government Email Requests

Revolut Tricked by Fake Government Email Requests

Revolut confirmed a breach after an attacker impersonated a government agency and sent fraudulent data requests from what appeared to be a legitimate government email domain. Employees processed the requests as normal legal-compliance work, leading to exposure of sensitive customer identity and…

September 14, 2026
Revolut Fooled by Fake Government Data Requests

Revolut Fooled by Fake Government Data Requests

Revolut confirmed it shared sensitive customer information with an unauthorized party after accepting fraudulent “government” information requests sent from an email address on a legitimate government domain. The company says this was an external impersonation scam (not a system hack) and that…

September 14, 2026
Fake Government Email Tricked Revolut for Data

Fake Government Email Tricked Revolut for Data

Revolut confirmed that an attacker impersonated a government agency using an email address on that agency’s real domain to obtain sensitive customer records. Revolut says only a limited number of customers were affected and that customer funds and Revolut systems were not accessed.

September 14, 2026
Fake Govt Email Tricked Revolut Into Sharing KYC

Fake Govt Email Tricked Revolut Into Sharing KYC

Revolut says it handed over sensitive customer identity and financial data after receiving what looked like a legitimate government information request. The email came from inside a real government agency’s email domain and passed authentication checks, so staff processed it before later…

September 12, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026