Revolut has confirmed that sensitive customer data reached an unauthorized third party after the British fintech fell for a batch of fraudulent information requests sent from what looked like a legitimate government agency’s own email domain. The company disclosed the incident on September 12, 2026, telling TechCrunch that the scam involved “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” according to a Revolut spokesperson quoted by the outlet.
The breach lands at an awkward moment for a company that has spent the last two years pitching itself as a bank-grade alternative to traditional lenders across more than 30 countries. Revolut has not said how many customers were affected, describing the number only as “limited.” But the categories of data involved, according to reporting from TechCrunch and Decrypt, go well beyond a typical marketing-list leak: birth dates, postal addresses, email addresses, phone numbers, and copies of government identity documents including passports and driver’s licenses. Decrypt also reported that verification selfies, account statements, and Bitcoin transaction histories may have been exposed for some affected users.
How the fake government request scam actually worked
The mechanics of this attack are what make it worth studying closely. Revolut did not suffer a network intrusion, a leaked database, or a stolen credential set in the conventional sense. Instead, the company received a request for customer records that appeared, on its face, to come from a real government agency. That request was sent from the agency’s own official email domain, meaning it passed the kind of authentication checks (SPF, DKIM, DMARC) that companies typically rely on to filter spoofed mail. Revolut’s compliance and legal teams treated the request as genuine, in keeping with standard practice for regulated financial firms that are legally obligated to respond to lawful government inquiries.
The problem is that “sent from the agency’s real domain” does not mean “sent by someone authorized to use it.” Attackers who compromise a single mailbox inside a government agency, or who gain access through a misconfigured mail relay, can send messages that carry every technical signal of legitimacy while having nothing to do with an actual investigation. Revolut later discovered the requesting account was fraudulent, blocked the address, and told TechCrunch it has since alerted the relevant government agency, law enforcement, and regulators. The company added that “Revolut systems and customer funds are unaffected,” drawing a distinction between the data exposure and any compromise of its core banking infrastructure.
This is not a new trick, and that is the uncomfortable part
Security researcher Brian Krebs documented this exact technique back in March 2022, when he reported that criminal hackers had been using compromised police and government email accounts to file fake Emergency Data Requests (EDRs) with major platforms. Krebs found that Apple and Meta had both handed over user data, including addresses, phone numbers, and IP addresses, in mid-2021 after being fooled by forged emergency requests, according to his reporting at the time.
An EDR exists for a legitimate reason: when there is a credible risk of imminent harm or death, investigators can request data without the delay of a full subpoena or warrant. That legal shortcut, useful in genuine emergencies, is exactly what attackers exploit. Once inside a single government mailbox, a scammer can invoke the language of an emergency, cite the agency’s real domain, and skip the paperwork trail that would normally raise flags. Krebs noted that the technique became reliable enough that criminal marketplaces began selling “fake EDR as a service” to other attackers. Four years later, a similar approach appears to have worked against Revolut, at far greater scale in terms of the sensitivity of documents handed over: full identity papers rather than just contact metadata.
The gap between 2022 and 2026 is instructive. Despite years of public warnings from researchers and even from the FBI (which flagged a rise in hacked police email accounts and fake subpoenas in a November 2024 advisory), the underlying weakness has not gone away: financial institutions and platforms still lean heavily on domain authentication as a proxy for legal authority, and that proxy remains gameable whenever a single government mailbox is compromised.
What data was exposed, by category
Revolut has not published a full breakdown or a hard number of affected accounts, so the table below reflects what has been reported across TechCrunch, Decrypt, and CyberSecurityNews rather than an official company disclosure. Some categories are confirmed on the record by Revolut. Others come from journalists’ review of the request and its aftermath and should be read as reported rather than officially confirmed.
| Data category | Status | Reported by |
|---|---|---|
| Date of birth | Confirmed by Revolut | TechCrunch |
| Postal address | Confirmed by Revolut | TechCrunch |
| Email address | Confirmed by Revolut | TechCrunch |
| Phone number | Confirmed by Revolut | TechCrunch |
| Passport copies | Confirmed by Revolut | TechCrunch, Decrypt |
| Driver’s license copies | Confirmed by Revolut | TechCrunch, Decrypt |
| Verification selfies | Reported, not officially detailed | Decrypt |
| Account statements | Reported, not officially detailed | Decrypt |
| Bitcoin transaction history | Reported, not officially detailed | Decrypt, CoinDesk |
| Exact number of victims | Not disclosed (described as “limited”) | TechCrunch |
Why the crypto angle matters more than it looks
Revolut is not a pure crypto exchange, but it has built a sizable crypto trading feature into its core app, letting retail users buy, hold, and move Bitcoin and other assets alongside conventional fiat balances. That is precisely why the reported inclusion of Bitcoin transaction histories in the leak stands out. Identity documents plus a record of crypto activity is a combination that fraud researchers describe as high-value bait: it lets a scammer approach a victim with specific, verifiable details (“we know you hold Bitcoin, we know your passport number”) that make follow-on phishing or extortion attempts far more convincing than a generic phishing email ever could be.
This pattern mirrors what happened after other high-profile fintech and exchange breaches, where the initial data exposure event was smaller in scope than the wave of targeted follow-up scams it enabled. Customers whose passport and crypto activity data was exposed in this incident should treat unsolicited calls or messages referencing their Revolut account or crypto holdings with heightened suspicion, even if the caller appears to know specific account details.
Revolut’s market position going into the disclosure
Revolut has spent recent years pushing hard toward full banking status across multiple jurisdictions, adding services that go well beyond its original currency-exchange app: stock trading, crypto, business accounts, and in some markets, a full banking license. That expansion has made the company a much bigger target for both financial and reputational attacks, because a data incident at a firm positioning itself as a bank draws different scrutiny than the same incident at a startup app. Financial regulators generally hold licensed banking entities to disclosure and data-protection standards that go beyond what a typical consumer tech company faces, which is part of why this story crossed so quickly from tech press into wire coverage.
The timing also matters. Fintech firms have been racing to add AI-assisted fraud detection and identity verification over the past year, precisely to catch anomalies like a legal request that does not match a requesting agency’s normal pattern of behavior. That this scam still got through suggests the weak link was procedural (how legal/compliance teams vet an inbound government request) rather than something a fraud-detection model watching transaction patterns would ever catch. It is a reminder that account-takeover defenses and back-office legal-request handling are two entirely different attack surfaces, and hardening one does nothing for the other.
How Revolut’s incident compares to other 2026 fintech and platform breaches
Revolut is far from alone in facing a data exposure event tied to social engineering rather than a technical exploit. The table below places this incident alongside a handful of other notable 2025-2026 breaches that involved trust-based manipulation of a company’s own staff or processes rather than a direct system compromise.
| Company | Attack vector | Data exposed | Disclosed number affected |
|---|---|---|---|
| Revolut (2026) | Fake government data request via spoofed real agency domain | ID documents, contact details, reported crypto activity | Undisclosed, described as “limited” |
| Trezor (2026) | Compromised email/support vendor, phishing follow-up | Email addresses, phishing exposure | Roughly 347,000 emails sent, per Trezor’s own disclosure |
| Manchester Airports Group (2026) | Third-party contractor compromise | Personal records | Approximately 8.7 million records reported |
| Apple / Meta (2021, referenced by Krebs) | Fake Emergency Data Request from compromised police email | Addresses, phone numbers, IP addresses | Not fully disclosed publicly |
The common thread across these incidents is not a shared piece of malware or a shared vulnerability class. It is that attackers increasingly find it easier to convince a human process to hand over data voluntarily than to break through technical perimeter defenses. Fintech companies in particular sit in an awkward spot here: they are legally required to respond promptly to genuine government and law enforcement requests, which creates institutional pressure to act quickly rather than verify slowly.
The regulatory exposure Revolut now faces
Revolut operates across the European Economic Area and the UK under banking and e-money licenses, which puts this incident squarely inside the scope of GDPR and the UK’s equivalent data protection framework. Under GDPR, a data controller that suffers a breach involving personal data must generally notify the relevant supervisory authority within 72 hours of becoming aware of it, and must notify affected individuals directly when the breach is likely to result in a high risk to their rights and freedoms. Handing over passport scans and identity documents to a fraudulent party is close to the textbook definition of a high-risk exposure, given how directly that data category enables identity theft.
Revolut has already drawn regulatory attention in the past over unrelated compliance matters as it has expanded its banking license footprint across the EU. A confirmed data breach involving government ID documents adds a fresh data point for regulators evaluating whether the company’s internal controls have kept pace with its growth. Fines under GDPR for serious data protection failures can reach up to 4% of global annual turnover, though actual penalties for breaches of this type have historically landed well below that ceiling, particularly when a company can show it acted quickly to contain and disclose the incident once discovered.
What Revolut customers should do right now
Anyone who banks or trades crypto through Revolut should treat this as a prompt to check their account activity and tighten a few basic defenses, even without knowing for certain whether their own data was among the records exposed.
- Enable two-factor authentication on the Revolut app if it is not already active, and use an authenticator app rather than SMS where the option exists.
- Watch for phishing calls or messages that reference specific account details, passport numbers, or crypto holdings, since exposed identity data makes these scams far more convincing than generic phishing attempts.
- Place a fraud alert or credit freeze with major credit bureaus if a passport or driver’s license number was likely exposed, since that document data can be reused well beyond a single platform.
- Change the email password associated with the Revolut account, particularly if the same password is reused elsewhere.
- Contact Revolut support directly through the official app, not through any link or number received in an unsolicited message referencing this breach.
The deeper industry problem: verifying who is really asking
The Revolut incident exposes a structural weakness that goes well beyond one company’s compliance process. Domain authentication protocols like SPF, DKIM, and DMARC were built to confirm that an email actually originated from the domain it claims to be from. They were never designed to confirm that the individual sending the email is authorized to make the request they are making. A compromised mailbox inside a legitimate government agency defeats every one of those protocols by design, because the message really did come from that domain.
Kodex, a startup founded by former FBI agent Matt Donahue, has been building tools since 2022 specifically to help tech and financial companies score the trustworthiness of inbound law enforcement requests, according to Yahoo Finance’s coverage of the broader trend and Krebs on Security’s original reporting at the time. The fact that this category of fraud is now hitting a major European fintech four years after that reporting suggests adoption of such verification layers remains inconsistent across the industry, and that many companies still rely primarily on domain-matching as their main defense.
Historical context: government impersonation fraud has a long tail
Fake legal process fraud is not a new invention of the AI era. Attackers have targeted the seams between legal obligation and identity verification for years, precisely because those seams involve humans making judgment calls under time pressure. What has changed since Krebs’s original 2022 reporting is the target profile: early fake-EDR fraud focused on social platforms and telecoms, chasing metadata like IP addresses and phone numbers useful for doxxing or account takeover. The Revolut case marks a shift toward a much richer target, a financial institution holding full identity documents, financial transaction histories, and crypto activity in one place, which raises the payoff for attackers willing to put in the work of compromising a government mailbox first.
That shift tracks with a broader trend across 2025 and 2026: attackers increasingly target the richest single repository of verified identity data they can find, rather than chasing scattered pieces of personal information across many smaller sources. A fintech company that has already done the work of collecting and verifying passports, proof of address, and transaction history for millions of users is, from an attacker’s perspective, a far more efficient target than assembling the same profile piecemeal from a dozen smaller breaches.
Predictions: what happens next
- Expect Revolut to face at least one formal regulatory inquiry from an EU or UK data protection authority within the next few months, given the sensitivity of the exposed identity documents.
- Expect a wave of targeted phishing attempts against Revolut customers over the coming weeks, particularly ones referencing crypto holdings, since that detail makes social engineering far more credible.
- Expect other fintech and crypto platforms to quietly review their own legal-request intake processes in the wake of this disclosure, even without public announcements, given how closely this mirrors the 2021-2022 fake-EDR wave documented by Krebs.
- Expect calls from privacy advocates and possibly lawmakers for standardized verification systems for law-enforcement and government data requests across the fintech sector, echoing the “credit rating for police requests” concept Kodex has pursued since 2022.
- Expect Revolut to publish additional detail on the scope of the breach only if regulatory notification requirements force disclosure of a more specific number, since the company has so far stuck to describing the impact as “limited.”
Frequently asked questions
What exactly did Revolut confirm about the breach?
Revolut confirmed that sensitive customer information was disclosed to an unauthorized third party after the company received fraudulent information requests sent from what appeared to be a legitimate government agency’s official email domain, according to a company spokesperson quoted by TechCrunch.
How many Revolut customers were affected?
Revolut has not disclosed an exact figure, describing the number of affected customers only as “limited,” per TechCrunch’s reporting.
What kind of data was exposed?
Confirmed categories include date of birth, postal address, email address, phone number, and copies of identity documents such as passports and driver’s licenses. Decrypt also reported that verification selfies, account statements, and Bitcoin transaction histories may have been involved for some users, though Revolut has not detailed those categories in its own statements.
Were Revolut’s systems or customer funds compromised?
No. Revolut told TechCrunch that its systems and customer funds are unaffected. The incident involved data being handed over to a fraudulent requester, not a direct intrusion into Revolut’s banking infrastructure.
What is a fake emergency data request, and is this the same thing?
An Emergency Data Request, or EDR, is a legal mechanism that lets investigators obtain user data quickly during situations involving imminent risk of harm, bypassing the normal subpoena process. Brian Krebs first documented criminals abusing this mechanism against Apple and Meta in 2021-2022 by using compromised police email accounts. The Revolut incident follows a similar pattern: a request sent from a real government domain, treated as authentic because it passed standard email authentication checks.
What should Revolut customers do to protect themselves?
Enable two-factor authentication through an authenticator app, watch for phishing attempts that reference specific account or crypto details, consider a credit freeze if passport or license data may have been exposed, and only contact Revolut support through the official app rather than any link received in an unsolicited message about this incident.
Could Revolut face fines over this breach?
Revolut operates under GDPR and UK data protection rules that require notifying regulators within 72 hours of discovering a breach and notifying affected individuals when the risk is high. Serious violations can theoretically draw fines of up to 4% of global annual turnover, though actual penalties for comparable incidents have typically landed well below that maximum.
Has this type of scam happened to other companies before?
Yes. Krebs on Security reported in 2022 that Apple and Meta had both been tricked into handing over user data through fake emergency data requests sent from compromised law enforcement email accounts. The technique became common enough that some cybercriminal groups began offering it as a paid service to other attackers.



