Revolut has confirmed a data breach after a scammer used a legitimate government agency’s email domain to submit fraudulent requests for customer information, and the fintech app says the request came through channels its staff normally treat as routine legal compliance. The company disclosed the incident on September 12, 2026, after security researcher ZachXBT flagged unusual account activity days earlier, and it says the intrusion exposed identity documents, verification selfies and financial records for a limited group of customers. Revolut has declined to say how many people were affected or which government agency’s domain the scammer impersonated.
The breach did not touch Revolut’s core banking systems or customer funds, the company says, and it stemmed entirely from an impersonation scheme rather than any technical intrusion into its own infrastructure. That distinction matters for a company that markets itself on security features like instant card freezing, because the weak point here was a human process, not a coding flaw.
A scammer used a real government domain to request records
Revolut described the method in stark terms: “an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” Because the email came from an authentic government domain rather than a spoofed lookalike address, it passed the checks Revolut’s compliance staff typically rely on when a real regulator or law-enforcement body asks for customer records, and the request was processed as if it were genuine.
Security researcher ZachXBT, a crypto investigator known for tracing stolen funds, first raised the alarm publicly on September 12, prompting Revolut to send breach notifications to affected customers the following day and to confirm the incident to reporters by September 14. The company has not said how the government agency’s own email system came to be compromised or misused, or whether that agency has separately acknowledged the impersonation.
Revolut’s statement went further than most breach disclosures in naming the broader trend behind it, describing “a growing category of fraud in which attackers exploit trusted institutional email domains, including those of government bodies, to bypass standard verification procedures used by financial services firms when responding to official data requests.” Reporting on the incident noted that the fraudulent email carried valid sender-authentication signals — the domain passed SPF, DKIM and DMARC checks that email systems normally use to weed out spoofed senders — which is part of why staff processing routine legal requests had no obvious reason to question it.
Passports, selfies and transaction histories exposed
The exposed data went well beyond basic contact details. Customer notices reviewed by Infosecurity Magazine listed full names, dates of birth, home addresses, phone numbers, occupations, copies of passports and driving licences, verification selfies, IBANs, account-opening dates, and transaction and withdrawal histories among the records the fraudulent request pulled. Some notices also referenced Bitcoin wallet reference numbers, suggesting the scammer specifically sought out customers with cryptocurrency activity on the platform.
Revolut said its security team blocked the fraudulent email address once the scheme was discovered, notified the impersonated government agency, alerted law enforcement and financial regulators, and contacted the customers whose records had been handed over.
Two regulators are now reviewing the response
The breach has landed on the desks of two separate regulators. The UK’s Financial Conduct Authority and Lithuania’s State Data Protection Inspectorate are both examining the incident, with the FCA saying it was “looking into steps being taken to address any harm.” Revolut is described as actively engaging with both regulators as the review continues.
Lithuania’s involvement follows from where Revolut actually holds its banking license. Revolut Bank UAB is licensed and supervised by the Bank of Lithuania, which granted the company a full banking license rather than the narrower electronic-money license Revolut operated under in its earlier years, giving Lithuanian authorities direct standing to examine how customer data was handled.
Under European data-protection rules, companies that suffer a breach affecting personal data generally have a tight window to notify their supervisory authority. The UK’s data-protection regulator, whose standard guidance calls for notification “as soon as possible, and where feasible within 72 hours” of a company determining a breach poses likely risk to people, can request additional details later even when a company’s initial report is incomplete. Revolut has not said publicly whether its September 12 disclosure met that standard for every regulator now reviewing the case.
What remains unresolved is simple: Revolut has not said how many customers were affected, and neither the FCA nor Lithuania’s privacy authority has yet announced findings from a review both confirmed they are conducting. An unverified claim posted online by an actor identifying itself only by a screen name alleged a far larger haul of records tied to the same incident, but Revolut has not confirmed those figures, and the company’s own public account still describes the exposure as limited to a small group of customers.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Amazon’s Prime refunds are rising to $200 as millions more customers become eligible
- A handful of car engines are so tough mechanics say they almost never wear out
- The NSA is again telling phone owners to switch off one location setting
- Supplements now rank as the fifth-leading cause of death from liver disease.