Revolut Tricked by Spoofed Government Email

Hackaday · Medium sophistication
Last updated September 18, 2026

Revolut confirmed a customer data breach after attackers used a compromised government agency domain to submit fake “official” requests for customer information. Revolut provided sensitive details (including IDs like passports and driver’s licenses) based on those email requests, raising questions about verification controls for law-enforcement or government inquiries.

Key findings

  • Attackers used a compromised/spoofed government domain to make requests that appeared legitimate.
  • Revolut provided customer data in response, including highly sensitive identity documents.
  • The article notes uncertainty about how many customers were affected and why email-only requests were sufficient without stronger validation.

Who’s being targeted

  • Commonly targeted roles: Customer Support, Compliance, Legal, Fraud/Investigations, Data Privacy, Security Awareness.
  • Affected industries: Financial services / Fintech, Banking, Cryptocurrency services.
  • Attack channels: email.
  • Impersonated: Government agency (using a compromised government domain).

Awareness takeaways

  • Treat ‘government’ or ‘law enforcement’ email requests as high-risk and require a strict verification process (approved intake channel, legal review, and callback to a known published number).
  • Never release identity documents or transaction history based on email alone; require documented authority and verified identity of the requester.
  • Assume trusted domains can be compromised; ‘looks official’ is not proof. Validate the request, not just the sender address/domain.

Red flags to watch for

  • Email request for sensitive customer data with no secondary verification (ticketing portal, signed request, callback, or warrant validation).
  • Urgent/authoritative tone implying legal pressure to bypass normal checks.
  • Request comes from a domain that may look legitimate but could be compromised or misused.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Revolut actually handed over passports and IDs because a fake ‘government’ email asked for them. Attackers used a compromised government domain and wrote, 'Hello Revolut Compliance Team, we are requesting customer details in relation to an official government inquiry. Please provide the customer’s address, date of birth, and identity documentation.' And Revolut sent it. Here’s the trap: the domain looked official, but it was compromised. There was no secure portal, no signed warrant, no callback to a published number, just an email, and they still released addresses, birthdates, and ID scans. If an email asks for customer data in the name of ‘government’ or ‘law enforcement,’ stop. Don’t reply. Route it through our official legal intake channel and let them verify it.

Similar attacks

Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Fooled by Govt Impersonation Email

Revolut Fooled by Govt Impersonation Email

A person posing as a government agency used an email address on that agency’s real domain to obtain sensitive customer records from Revolut. The same weekly roundup also describes a fake antivirus renewal web page impersonating Avast, telling victims their subscription renewed for €129.99 and…

September 20, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Revolut Tricked by Fake Government Email Requests

Revolut Tricked by Fake Government Email Requests

Revolut confirmed a breach after an attacker impersonated a government agency and sent fraudulent data requests from what appeared to be a legitimate government email domain. Employees processed the requests as normal legal-compliance work, leading to exposure of sensitive customer identity and…

September 14, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Revolut Tricked by Stolen Govt Email

Revolut Tricked by Stolen Govt Email

Attackers used a compromised government email account to pose as authorities and request customer records from Revolut. Employees believed the requests were legitimate and voluntarily sent sensitive customer information, exposing data for nearly 700 people. The incident highlights how “trusted”…

September 18, 2026