Story
September 16, 2026
Fake Government Emails Duped Revolut Into Releasing Customer Data
Revolut portrays the episode as an external impersonation scam rather than a breach of its own systems, while the scale and sensitivity of the records disclosed underline how damaging a convincing government-email ruse can be for customers.
Revolut has confirmed that scammers persuaded the fintech to disclose customer data by sending fraudulent information requests from a legitimate government agency email domain — an attack that bypassed trust, not its technical defences.
The episode surfaced late Friday when crypto-security researcher ZachXBT posted about an email sent to affected customers. The researcher said the apparent targets were high-net-worth users, raising the stakes of what Revolut initially characterised as a limited incident.1
According to the customer notification reviewed by TechCrunch, the disclosed material included identity and contact details — dates of birth, postal and email addresses, and phone numbers — alongside copies of passports or driving licences. Revolut warned that verification selfies, account statements and transaction histories may also have been included.1
Revolut said the requests came from an unauthorised third party using the real domain of a government agency. “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” a spokesperson said.1
The company said it blocked the offending email address after discovering the fraud, contacted affected customers and alerted the relevant agency, law enforcement and regulators. It declined to identify the agency, say whether one market was involved, or disclose an exact victim count. Its central assurance was unequivocal: “Revolut systems and customer funds are unaffected.”1
That reassurance sits beside a more troubling estimate: Revolut reportedly handed scammers the data of nearly 700 customers.2 For a company with more than 80 million users and expanding banking ambitions, the incident is a reminder that a trusted-looking inbox can be as consequential as a compromised network.