Revolut Tricked by Fake Government Email Requests

Infosecurity Magazine · High sophistication
Last updated September 14, 2026

Revolut confirmed a breach after an attacker impersonated a government agency and sent fraudulent data requests from what appeared to be a legitimate government email domain. Employees processed the requests as normal legal-compliance work, leading to exposure of sensitive customer identity and account information for a limited number of customers.

Key findings

  • An unauthorized third party submitted “fraudulent requests for information” using a “legitimate government agency domain email.”
  • Revolut called it “a sophisticated external impersonation scam” and said the requests had “valid technical domain authentication.”
  • Revolut employees fulfilled the requests as standard legal compliance, resulting in disclosure of sensitive customer data.
  • Reportedly exposed data included PII (name, DOB, address, phone, email, occupation) plus identity documents and selfies; a researcher also alleged exposure of financial details (IBANs, transaction/withdrawal history, Bitcoin wallet reference numbers).
  • Revolut said systems and customer funds were not affected and it blocked the address, notified customers, and alerted authorities and regulators.

Who’s being targeted

  • Commonly targeted roles: Legal, Compliance, Privacy/Data Protection, Customer Support/Operations, Fraud/Investigations, Security Awareness (customer communications).
  • Affected industries: Financial services / fintech.
  • Attack channels: email.
  • Impersonated: Government agency (using a legitimate government agency email domain).

Awareness takeaways

  • Treat emailed ‘government/legal’ data requests as high-risk and independently verify the requester through known, official channels before sharing any customer data.
  • Train teams that handle sensitive data (legal/compliance/privacy/operations) that a real-looking sender domain is not enough, attackers can impersonate trusted entities convincingly.
  • Warn customers to expect follow-on scams after a breach and to avoid sharing passcodes or one-time security codes with anyone contacting them unexpectedly.

Red flags to watch for

  • Request comes via email and asks for unusually broad/sensitive records
  • Relies on the sender domain appearing legitimate rather than independent verification
  • Process pressure: treated as “standard legal compliance” without stronger validation
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this lands in your inbox: “Request for information, legal compliance. Please provide the requested customer records.” And it’s from a real government email domain. That’s exactly how Revolut was tricked. An unauthorized third party used a legitimate government agency domain with valid technical authentication, so the emails passed all the usual checks and were treated as standard legal work. Employees fulfilled the requests and sent over names, addresses, dates of birth, phone numbers, emails, ID documents, even transaction history. All because the sender domain looked right and the process felt routine. Your move: if an email claims to be a government or legal data request, stop. Don’t reply. Independently verify it using a phone number or portal you already trust before sending a single record.

Similar attacks

ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Revolut Hit by Govt-Agency Email Impersonation

Revolut Hit by Govt-Agency Email Impersonation

Revolut says a third party posing as a government agency tricked the company into disclosing some customers’ personal and financial data. The attacker used an email address on a legitimate government agency domain, causing the request to be treated as a real legal inquiry. Revolut says customer…

September 14, 2026