Revolut has confirmed a Revolut data breach triggered by a fake government request, in which a threat actor impersonating a government agency obtained sensitive customer data, including passport copies, facial verification images, and full transaction histories. The company operates in over 160 countries and regions and serves more than 80 million customers worldwide, including 800,000 business customers.
How the Fake Government Request Got Through
The attacker sent an email to Revolut using a government agency’s official email domain. According to emails sent to affected customers, ‘the request came from an unauthorised email account sent directly using the official government agency’s email domain,’ and because ‘the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.’
That is the crux of the problem: the email passed standard authentication checks. Domain-based authentication, the kind that most organisations rely on to separate legitimate correspondence from phishing, was apparently satisfied, leaving Revolut with little technical basis to question the request before complying.
The breadth of data handed over is considerable. Revolut confirmed that affected customers’ information includes identity details (full name, date of birth, occupation), contact details (postal address, email address, telephone number), copies of identity documents such as passports and driver’s licences, and facial verification images gathered during Know Your Client onboarding. Also exposed: account statements including IBAN numbers, withdrawal records, and full transaction histories, including Bitcoin transactions.
The company told Reuters that only a ‘very limited’ number of customers are affected, though it has declined to give a precise figure. ‘Revolut systems and customer funds are unaffected. Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,’ a Revolut spokesperson said.
A Known Attack Pattern, With an FBI Warning Already on the Books
The method used against Revolut is not new. The FBI warned in November 2024 that compromised government email accounts were being actively sold and used to submit fraudulent emergency data requests to companies, according to Zyphe. That warning came with specific detail: as American Banker reports, the FBI’s notification documented a seller claiming to control government email accounts in more than 25 countries.
The Revolut breach fits squarely into that pattern. Emergency data requests are a legitimate mechanism used by law enforcement to obtain user information quickly in urgent situations, but criminals have identified them as a route to sensitive data precisely because companies are inclined to comply promptly. American Banker also reports that a criminal posted photographs on a forum in March 2024 of a fraudulent request sent to PayPal, illustrating that Revolut is far from the first financial services company to be targeted this way.
Crypto fraud investigator ZachXBT added a further layer of detail over the weekend, saying that while the breach likely affects a limited number of Revolut customers, ‘it seems to have been targeted at high net worth users.’ That framing suggests this was not a bulk data-scraping operation but a calculated attempt to gather actionable financial intelligence on specific individuals.
Not the First Time, and the Stakes Are Higher Now
This is not Revolut’s first data breach disclosure. Four years ago, attackers accessed and stole personal, contact, and financial information belonging to 50,150 customers in September 2022. The company disclosed that incident and has since grown substantially, which raises the stakes of any subsequent security failure.
The timing is particularly awkward. Reuters reports that Revolut is planning for a potential public listing and is aiming for a valuation of up to $200 billion. A breach involving passports, selfies, full transaction records and IBAN numbers, even one affecting a ‘very limited’ number of customers, is not the kind of headline any company wants attached to its pre-IPO narrative. Whether regulators, already alerted according to the company’s own statement, share Revolut’s apparent confidence that the damage is contained remains to be seen from their filings and any subsequent enforcement actions.

