Revolut Confirms Customer Data Breach Linked to Fake Government Requests
Key Takeaways
- •Revolut disclosed customer data after fraudsters sent requests from an email address impersonating a government agency, and the messages successfully passed SPF, DKIM, and DMARC authentication checks.
- •Compromised information included names, birth dates, contact details, identification documents, transaction histories, and account statements, but no customer funds were stolen and core banking systems were not compromised.
- •The company has not revealed how many users were affected, though reports indicate higher-net-worth individuals may have been specifically targeted and analyst ZachXBT described the incident as limited in scale.
- •Revolut blocked the fraudulent email address and contacted regulatory bodies, law enforcement, and the impersonated government agency, whose identity has not been publicly identified.
- •This is Revolut's second known data security incident, following a 2022 breach that affected tens of thousands of customers through the social engineering of an employee.

Revolut, the British fintech company, confirmed on September 12 that it disclosed sensitive customer information after receiving fraudulent data requests from an email address impersonating a legitimate government agency.
The spoofed messages passed SPF, DKIM, and DMARC authentication checks, the three main protocols email servers use to verify whether a message came from an authorized source and whether its contents were altered. These checks help validate an email’s technical origin and integrity, but they do not by themselves establish that a request is genuinely from the government agency it claims to represent. The incident was described by Revolut as a “sophisticated external impersonation scam.”
Data exposed and customers targeted
The compromised information included customers’ full names, birth dates, contact details, copies of identification documents, transaction histories, and account statements. Revolut said that no biometric facial telemetry data was shared, no customer funds were stolen, and its core banking systems were not compromised.
The company has not disclosed the exact number of affected users. Reports indicate that a select group of higher-net-worth individuals may have been specifically targeted. On-chain analyst ZachXBT said the incident appeared to be limited in scale. Customer notifications began circulating around September 11, one day before Revolut publicly confirmed the breach.
How the fraudulent requests passed email safeguards
SPF checks whether the sending server is authorized to send email on behalf of a domain. DKIM verifies that the message content was not tampered with while in transit. DMARC connects those checks and instructs receiving servers how to handle messages that fail authentication.
Despite those safeguards, the fraudulent emails passed all three protocols. Revolut said it blocked the fraudulent email address, contacted regulatory bodies and law enforcement, and reached out to the government agency whose identity had been impersonated. The company has not publicly identified that agency.
The incident shows why authenticated email alone is not a complete verification process for sensitive data requests. The messages passed technical checks even though the requests themselves were fraudulent, making the company’s follow-up with regulators, law enforcement, and the impersonated agency part of the continuing response.
Earlier security incident
The latest breach is not Revolut’s first data security incident. In 2022, the company experienced a breach affecting tens of thousands of customers. That incident involved unauthorized access resulting from the social engineering of an employee. The latest episode instead targeted the compliance process itself rather than individual staff credentials.
The incident comes as Revolut pursues expansion across Europe and beyond and signals ambitions toward a public listing. For customers, the immediate risk is informational rather than financial. Identification documents and transaction histories can be used in identity theft, targeted phishing campaigns, and social engineering attacks.
Source: CryptoBriefing