Revolut Says Scammers Used Real Government Email to Obtain Client Data

Revolut confirmed fraudsters used a legitimate government email domain to obtain customer data, including passports and bitcoin records.

12/09/2026 09:419 min read

Revolut has acknowledged that fraudsters deceived the platform into disclosing customer information, which the company's own alerts indicate included passport details, verification selfies and bitcoin transaction records.

The request arrived from an authentic government agency email domain and carried valid credentials. Believing it was legitimate, Revolut released the data.

What Revolut Says Happened

A Revolut representative told BeInCrypto that the bank blocked the sender as soon as it identified the issue.

“Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information… Revolut systems and customer funds are unaffected.”

The firm stated that it alerted the agency, the police, and its data protection and financial regulators. It has contacted the individuals it calls a limited number of affected people.

Are Revolut Accounts Secure?

Accounts remain safe, Revolut insists. That is accurate. The bank told BeInCrypto that passcodes, login details and biometric data were never exposed. No funds were moved.

The notices sent to customers tell a different story. They state that the verification selfie was included, and only rule out biometric facial telemetry — the face template a system builds from a photo. The photo itself is a separate matter.

Those notifications list the rest: passports, driving licences, home addresses and bank statements. A complete record of bitcoin inflows and outflows.

Revolut declines to say which agency's domain was used, citing the ongoing police investigation. So nobody outside the company knows whether a government mailbox was hijacked or whether someone already inside it sent the request.

Blockchain investigator ZachXBT, who traces stolen crypto for a living, flagged the breach, noting that it reached a small group of users and appeared aimed at wealthy ones.

Woke up to all my data leaked by @Revolut.

Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way. pic.twitter.com/RimOBQr7DW

— Marc Zeller (@mzeller) September 12, 2026

Stolen customer lists have fed phishing risks after breaches. Leaked home addresses have preceded violent attacks on holders.

Revolut has described this as a sophisticated attack. But by its own account, the attacker used a legitimate government email system to send a fraudulent request. Revolut accepted that request as genuine and released the data.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles