Revolut customer data exposed in phishing attack that bypassed email security checks
Key Takeaways
- •The attacker obtained customer records through social engineering rather than by penetrating Revolut’s internal systems.
- •Exposed information included identity documents, verification selfies, personal details, IBANs, withdrawal histories, and Bitcoin transaction activity.
- •The fraudulent request passed SPF, DKIM, and DMARC checks and appeared to use a legitimate government agency’s email domain.
- •Revolut said no passwords, PINs, private keys, or customer funds were compromised.
- •The company blocked the unauthorized email address, notified authorities, and has not disclosed the exact number of affected customers.

Revolut, the British fintech company pursuing a banking license and a potential valuation of around $200 billion, disclosed sensitive customer data to an individual impersonating a government official. The attacker did not breach Revolut’s systems but instead used a convincing email to request the information.
Revolut described the incident as a “sophisticated external impersonation scam.” The exposed information included identity documents, verification selfies, full names, dates of birth, contact details, financial records such as IBANs, withdrawal histories, and Bitcoin-related transaction activity. The company began notifying customers on September 11, 2026. The incident was reported by CryptoBriefing.
How the fraudulent email passed security checks
The request appeared to originate from the email domain of a legitimate government agency. More significantly, it passed SPF, DKIM, and DMARC checks, three email-authentication protocols used to verify a sender’s identity and the integrity of a message.
SPF confirms that an email was sent from an authorized server. DKIM verifies that the message was not altered while in transit. DMARC connects those checks and specifies how a recipient should respond if either one fails. In this case, all three checks passed.
As a result, Revolut’s compliance team had technical grounds to consider the request authentic. The team processed it and provided customer records to an unauthorized third party who had created what appeared to be valid credentials without accessing Revolut’s internal systems.
No passwords were stolen, and no PINs or private keys were compromised. Revolut also said that no customer funds were moved. However, personal and financial records were disclosed through the company’s process for handling official data requests.
Bitcoin transaction data among exposed records
The inclusion of Bitcoin transaction histories adds a cryptocurrency-specific dimension to the incident. When combined with identity documents and verification selfies, such information could provide bad actors with material for identity fraud, social-engineering attempts, or targeted phishing campaigns aimed at crypto holders.
Revolut described the number of affected customers as “limited” but has not disclosed an exact figure. Awareness of the incident increased after affected individuals, including notable figures in the crypto industry, shared details of the notifications they received.
Attack targeted compliance procedures
The incident did not involve a zero-day exploit or a compromised database. Instead, it was a social-engineering attack aimed at Revolut’s compliance workflow for responding to official government data requests.
Revolut has blocked the unauthorized email address and notified law-enforcement authorities and relevant regulatory agencies. The company said its systems remain uncompromised and that no customer funds were affected.
Incident comes amid licensing and listing efforts
The disclosure comes as Revolut pursues a banking license, a process subject to regulatory scrutiny of operational controls, including procedures for handling sensitive customer information. The company has also been exploring a public listing with a target valuation of around $200 billion.