Revolut has confirmed a Revolut data breach in which an unauthorised third party obtained customer data by sending fraudulent information requests from a legitimate government agency email domain. The fintech says a limited number of customers were affected and that funds are safe. The method is what makes this one worth reading closely: nothing was hacked in the conventional sense. The attacker used a real government domain and the legal process that obliges companies to answer it.
Skip ahead
What Revolut has confirmed
According to TechCrunch, which reported the confirmation on 12 September, Revolut described the incident as a sophisticated external impersonation in which a third party used a genuine government agency domain to submit fraudulent requests for customer information. Bloomberg reported the company’s statement the same day.
Revolut says it blocked the address once it identified the scheme and notified the relevant government agency, financial regulators, law enforcement and data-protection authorities. The company’s characterisation of the scale — a limited number of customers — is its own, and has not been independently quantified.
What was exposed, and what was not
The exposed material, per the company’s disclosure and subsequent reporting, includes identity and contact details: date of birth, postal and email addresses and phone numbers. It also includes copies of identity documents such as passports and driving licences, and may include verification selfies, account statements and transaction histories.
Revolut says passwords and full payment card details were not accessed, and that customer funds are safe.
That split matters, and not in the reassuring direction most breach notices imply. Passwords can be changed. A passport scan paired with a verification selfie, a date of birth and an address cannot be. That combination is precisely the bundle used to pass remote identity checks at banks, crypto exchanges, mobile carriers and government portals. Help Net Security’s summary sets out what is known so far.
Why fake law-enforcement requests work
Financial firms and online platforms receive a steady stream of lawful requests for customer data from police, regulators and prosecutors. A subset are marked urgent, on the basis that a delay could cost a life or let a suspect flee. Companies are expected to respond quickly, and the main authenticity signal available to a reviewer is that the request arrived from an official government email domain.
That is a weak signal. Government mailboxes are compromised regularly, through phishing, credential stuffing or reused passwords, and a compromised mailbox grants exactly the one thing the fraud needs. The request itself can be well-drafted; the domain does the vouching.
The defence is procedural rather than technical: out-of-band verification by calling the agency back on a published number, mandatory secondary approval for identity-document disclosure, rate limiting on any single requester, and treating an urgent flag as a reason for more scrutiny rather than less. None of that is exotic. It is slow, which is why it erodes under volume.
What affected customers should do
If you receive a notification from Revolut, the useful steps are narrow and specific:
- Assume identity-theft risk, not account-takeover risk. Passwords were not taken; your documents may have been. The threat is someone opening accounts as you elsewhere.
- Place a credit freeze or fraud alert with the credit bureaus in your country. This is the single highest-value action and it is usually free.
- Expect targeted phishing. An attacker holding your date of birth, address and transaction history can write a far more convincing message than the usual spam. Treat any inbound contact about the breach as suspect and use the app, not a link.
- Enable a passkey or hardware key if your accounts support it, and review devices authorised on the Revolut app.
- Note the date. If you later dispute a fraudulent account opened in your name, being able to point to a documented breach and notification date is useful.
For regulators, the open question is whether the disclosure meets the notification standards of the jurisdictions Revolut operates in, and whether the agency whose domain was abused will say anything about how it was compromised. That second answer is the one that would help every other company facing the same request queue.
Frequently asked
What happened in the Revolut data breach?
An unauthorised third party used a legitimate government agency email domain to send fraudulent requests for customer information, and Revolut supplied data in response before identifying the scheme.
What data was exposed?
Identity and contact details including date of birth, postal and email addresses and phone numbers, plus copies of identity documents such as passports and driving licences. It may also include verification selfies, account statements and transaction histories.
Were passwords or card details taken?
Revolut says no passwords and no full payment card details were accessed, and that customer funds are safe.
How many customers were affected?
Revolut has described it as a limited number. The company has not published a figure, and the scale has not been independently verified.
What is an emergency data request scam?
A fraud in which an attacker sends a company an urgent-looking law-enforcement request from a compromised or spoofed official email account, relying on the company’s obligation to respond quickly to lawful requests.
What should I do if I am affected?
Freeze your credit file or place a fraud alert, expect targeted phishing, strengthen authentication on your accounts, and keep a record of the notification date.

