Skip to main content

On 12 September 2026, Revolut confirmed that sensitive customer information had been disclosed to an unauthorised third party following fraudulent requests sent from an email account associated with a legitimate government agency domain. Revolut described the event as a "sophisticated external impersonation scam" and said its systems and customer funds were unaffected.[1] [2] 

We will see below that the full details of the incident are not yet known, but what makes it particularly interesting is the apparent attack path. Based on what is currently public, the attacker did not need to penetrate Revolut's infrastructure. Instead, they appear to have exploited the trust placed in a legitimate information-request process. For banks, fintechs, payment providers, digital asset businesses and other entities holding valuable identity and transaction information, the distinction is important and offers lessons for their own organisations.

Edward Starkie
Edward Starkie

Director, GRC | Cyber Risk

estarkie@thomasmurray.com

Let's start with what we know

Revolut has confirmed that the fraudulent requests came from an email address on a legitimate government agency domain. It says a "very limited" number of customers were affected, that those customers were notified, that the offending address was blocked, and that the relevant government agency, law enforcement, data-protection authorities and financial regulators were informed.[1]

Notifications reviewed by TechCrunch indicate that possible data loss could include dates of birth, postal and email addresses, telephone numbers and copies of identity documents such as passports and driving licences, as well as verification selfies, account statements and transaction histories.[2] Additional reporting indicates that the data potentially included IBANs, withdrawal records and full transaction histories, including Bitcoin transactions.[3] For individuals affected, this combination of data points, used together, could provide valuable material for later impersonation, phishing, identity fraud and highly targeted social engineering. Precautions will likely need to be taken.

For the everyday customer, the real-world risk is less about the breach itself and more about what it enables next. A fraudster holding a genuine passport scan, a home address and a transaction history does not need to guess: they can call, text or email posing as Revolut, cite real account details to sound credible, and push a victim towards a fraudulent transfer or a fake "security verification". That is a materially more convincing scam than the generic phishing most people have learned to spot, which is precisely why the exposure of this kind of data matters even without confirmed financial losses. The episode is also a reputational test for Revolut. Customers bank with a digital-only provider on the promise that, absent a branch or a face-to-face relationship, their money and data are safe; a breach touching passports, selfies and transaction histories cuts at that promise, regardless of how the incident is ultimately attributed. Revolut’s prompt and relatively detailed disclosure may help limit the reputational damage, but in a fintech market where switching provider takes a few taps, trust lost here could shape customer perception and regulatory scrutiny well beyond the resolution of the technical details.

Just as importantly, what don't we know?

At the time of writing, Revolut has not disclosed several details, including exactly how many customers were affected, the identity of the government agency, or whether the incident was limited to a particular market.[2] Details of how the attacker came to control or use the legitimate government email account are also not known, and it would therefore be premature to say that the relevant government agency was "hacked" or to attribute a particular compromise method. We also do not know how many fraudulent requests were submitted, how long the activity continued, exactly what checks were performed before information was released, or whether existing procedures were bypassed or proved insufficient.

There is currently no public evidence proving that affected customers have suffered direct financial losses as a consequence of the disclosure. In short, many details remain unknown and may or may not emerge over time; we plan to monitor the situation and provide updates as needed. The lesson for other organisations is therefore not that Revolut definitively failed to operate a particular control, we simply do not know that, but rather that the incident raises important questions about how organisations establish the authority behind apparently legitimate information requests.

A known attack technique

This type of attack is not new. In November 2024, the FBI warned that attackers were gaining access to US and foreign government email addresses and using them to submit fraudulent emergency data requests to companies. The FBI specifically warned that this could expose customers' personally identifiable information and noted increased discussion of the technique on criminal forums.[4] The FBI advised private-sector organisations receiving law-enforcement requests to apply critical scrutiny rather than allowing urgency to shortcut validation, and to contact the sender and originating authority where verification is required.[4]

It should be recognised that threat actors continue to evolve their techniques, and that keeping track of all threat intelligence is challenging. However, the Revolut incident illustrates a broader problem: a technically authentic communication can still represent an illegitimate request.

What should organisations do?

  1. Review how sensitive information can legitimately leave the organisation. Organisations should map government and law-enforcement requests, regulatory disclosures, customer-service processes, account recovery and other mechanisms through which employees can legitimately access or release sensitive information. Particular attention should be paid to how identity and authority are established, when secondary approval is required and how exceptional or urgent requests are handled.
  2. Test the process, not just the technology. Traditional penetration testing remains vitally important, along with other technical testing, but organisations should also ask whether an attacker could manipulate an otherwise legitimate process. A tabletop exercise or simulation could recreate a request apparently originating from law enforcement and test how legal, compliance, privacy, security and operational teams respond.
  3. Understand how trusted identities are being abused. Threat intelligence should extend beyond malware and conventional vulnerability information to include compromised credentials, impersonation, criminal discussion of relevant attack techniques and exposure of trusted organisations.
  4. Extend the same thinking to third parties. The trusted identity being abused may belong to a government body, supplier, professional adviser or technology provider. Organisations therefore need to understand not only their own security controls, but the dependencies and trusted relationships surrounding them.

Takeaways: trust is part of the attack surface

The Revolut incident shows an increasingly important dimension of cyber risk. Organisations have spent years making it harder for attackers to gain unauthorised access. MFA, endpoint security, vulnerability management, privileged-access controls and monitoring all remain essential. But attackers do not necessarily need to defeat those controls at all: if they can compromise a trusted identity or manipulate a legitimate business process, they may be able to persuade an authorised individual to perform an authorised action for an unauthorised purpose.

That means organisations need to think about their attack surface more broadly. The question is no longer simply, "Can an attacker get into our systems?" It should also be, "Could an attacker persuade us to give them what they want without ever having to break in?"

For organisations holding sensitive financial and identity information, testing that assumption of trust must become an important part of cyber resilience.

This is, in practice, what distinguishes the organisations customers most want to bank with. They are not waiting for their own version of this headline: they are pressure-testing information-release processes, rehearsing impersonation scenarios before an attacker stages one for real, and bringing in an external partner such as Thomas Murray to challenge assumptions their own teams are too close to see. That is the difference between an organisation that has controls and one that has actually tested them.

Next steps

Thomas Murray helps organisations across the globe improve their cyber resilience, providing threat-led cybersecurity services to assess and manage cybersecurity within an organisation and across complex ecosystems. See a selection of our specific services below, or reach out to one of our consultants to book a 30-minute call and explore how we can help your organisation test, validate and improve its cyber resilience.

References

[1] Reuters, 12 September 2026, Revolut confirms sensitive customer data breach after fake government requests

[2] TechCrunch, 12 September 2026, Revolut confirms customer data breach through fake government requests

[3] The Block, 12 September 2026, Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov't domain

[4] Federal Bureau of Investigation, 4 November 2024, Easy Access to Information for Conducting Fraudulent Emergency Data Requests Impacts US-Based Companies and Law Enforcement Agencies, Private Industry Notification 20241104-001.

Cyber Risk

Incident Response

Thomas Murray’s incident response team is trained to respond quickly and efficiently to incidents and help your business get back on track.

Learn more