Story
September 16, 2026

Fake Government Emails Tricked Revolut Into Releasing Customer Files

Revolut says fraudsters using a legitimate government email domain secured sensitive customer records without breaching its systems or touching funds. Reports put the number affected at nearly 700, raising fresh questions over safeguards for official data requests.

Revolut has confirmed that scammers posing as a government agency persuaded the fintech to disclose sensitive customer information — not by breaking into its systems, but by exploiting trust in an official-looking email channel.

The scheme relied on a “legitimate government agency domain email” used to submit fraudulent information requests, Revolut said. The company discovered the impersonation, blocked the address and notified the relevant agency, law enforcement and regulators.

According to the notification sent to affected customers, the material released may have included names, dates of birth, postal and email addresses, phone numbers, passports or driver’s licences, verification selfies, account statements and transaction histories. Revolut described the number affected as “limited” and said it had contacted those customers directly, while maintaining that “Revolut systems and customer funds are unaffected.”

A separate report put the toll at nearly 700 customers, sharpening the gap between Revolut’s limited public accounting and the scale suggested by reporting. The company did not publicly identify the government agency whose domain was abused, say whether one market was particularly affected, or provide its own exact count.

The episode is especially awkward for a fast-expanding financial platform that serves more than 80 million customers globally. Security researcher ZachXBT, who flagged Revolut’s customer email, said the apparent targeting pointed toward high-net-worth users — a claim that, if borne out, would suggest a deliberate hunt for more valuable accounts rather than indiscriminate phishing.

For Revolut, the immediate message is containment: the breach was a social-engineering failure, not a compromise of its infrastructure. For affected customers, the distinction offers little comfort when identity documents and transaction records may already be in criminal hands.