A fraudster who wanted the personal records of Revolut customers did not hack a server or crack a password. They sent a request that looked like it came from a government agency, and it sailed through every technical check Revolut had in place. On September 12, the company confirmed that it handed sensitive customer data to an unauthorized third party as a result.
The request arrived from a real government email domain, according to Revolut, and passed all three authentication protocols that are supposed to verify a sender’s identity: SPF, DKIM and DMARC. Those checks are the industry’s standard defense against forged email, and a message that passes all three is normally treated as legitimate. In this case, the sender was impersonating the agency.
What went out the door was substantial. The exposed data included passports and driver’s licenses, verification selfies, names, dates of birth, addresses, phone numbers, IBANs, account statements and full encrypted transaction records. Funds, passwords, PINs and private keys were not affected, the company said, a line intended to reassure customers that the thieves could not empty accounts.
Revolut described the incident as a “sophisticated external impersonation scam” and said the number of affected customers was limited. The company said it had banned the address involved and notified the relevant institutions, regulators and law enforcement. It did not say which government agency the fraudster had impersonated, or how many customers were caught up.
The breach lands at an awkward moment. Revolut is pressing toward an initial public offering at a valuation of about $200 billion and has just received conditional approval for a U.S. national bank charter, a step that would let it hold deposits across the country. A data incident in the run-up to a listing gives investors one more thing to scrutinize, and gives regulators a reason to look harder.
The on-chain analyst known as ZachXBT said the attack appeared to target high-net-worth users, the customers whose accounts hold the most value and whose data commands the highest price. That detail, if it holds, would mean the fraudster was not fishing at random but working from a list, a sign of preparation rather than opportunism.
The method the attacker used points at a weakness no firewall can fix. Revolut’s systems did exactly what they were designed to do: they verified that the email came from where it said it came from. The failure was human, in the judgment that a verified government request should be honored. The company is one of a growing number of firms that have learned that email authentication proves only that a message was not forged, not that the request inside it is real.
Banks and fintechs have seen a wave of such attacks, in which fraudsters use stolen or spoofed government email addresses to demand customer records under the pretense of an investigation. The requests are urgent, cite legal authority and arrive through the same channels legitimate agencies use. For a firm like Revolut, which handles millions of accounts across dozens of countries, telling the difference is a job that grows harder as the company grows.
The company’s disclosure follows a pattern that has become standard for such incidents: confirm quickly, state what was and was not exposed, and promise to cooperate with authorities. What is less standard is the context. Few companies have faced a breach of this kind while asking public investors to value them at $200 billion.
Revolut has grown from a prepaid card app into a financial super-app that says it serves tens of millions of customers across dozens of countries, with ambitions in banking, trading and crypto. Its co-founder and chief executive, Nik Storonsky, has pushed the company toward a public listing that would rank among the largest fintech debuts ever. The national bank charter Revolut just received, conditioned on approval, would extend its reach in the United States, its most contested market.
The breach touches the trust that underpins that growth. A fintech that holds passports, selfies and full transaction histories is a custodian of the kind of records that enable identity theft when they leak. The fact that Revolut’s own systems passed the request through shows the limits of the checks the industry has come to rely on, and it gives competitors a chance to argue that their own controls would have caught what Revolut missed.
For Revolut’s customers, the immediate question is whether their documents are now circulating. The company has said the affected group is limited, but it has not named the individuals, and the nature of the data means the harm could surface months or years later. For Revolut, the harder question is whether the controls that let a fraudster walk out with passports and IBANs will satisfy the regulators who will decide how much the company is worth.


