Cobo Agentic Wallet

Revolut Confirms Data Exposure After Attackers Used Fake Government Requests

Revolut says an unauthorized party used an authentic government agency email domain to submit fraudulent information requests, leading to the disclosure of sensitive data belonging to a limited number of customers. The company has notified affected users and reported the incident to the relevant government agency, law enforcement, and regulators.

Cobo Newsroom
Cobo NewsroomSep 13, 2026
Key takeaways
  • The incident involved fraudulent requests sent from a legitimate government agency domain rather than a disclosed direct compromise of Revolut’s core systems.
  • Potentially exposed information included dates of birth, addresses, email addresses, phone numbers, identity documents, verification selfies, account statements, and transaction histories.
  • The company described the number of affected customers as limited but did not provide an exact figure or identify the government agency involved.
  • The records may have included Bitcoin activity, adding a digital-asset privacy dimension to the broader financial-data breach.
  • Revolut says it blocked the relevant email address and notified the government agency, law enforcement, and regulators; it also says customer funds and its systems were unaffected.
  • The case highlights the need for financial institutions to authenticate the authority and scope of government requests through independent channels, rather than relying on an email domain alone.

News illustration

Summary

Revolut says an unauthorized party used an authentic government agency email domain to submit fraudulent information requests, leading to the disclosure of sensitive data belonging to a limited number of customers. The company has notified affected users and reported the incident to the relevant government agency, law enforcement, and regulators.

A breach of trust rather than a disclosed systems intrusion

Revolut has confirmed that an unauthorized third party used the email domain of a legitimate government agency to submit fraudulent requests for customer information. The company said it identified the activity as a sophisticated external impersonation scam after information had been disclosed, then contacted the customers it believed were affected.

A notification sent to affected customers, reviewed by TechCrunch, said the exposed material may have included identity and contact details such as dates of birth, postal addresses, email addresses, and phone numbers. Copies of passports and driver’s licenses may also have been involved. The notification further listed verification selfies, account statements, and transaction histories as possible categories of exposed data.

The company has described the number of affected customers as limited, but it has not disclosed an exact total. It has also not said whether the incident was confined to a specific market or identified the government agency whose domain was used. Those omissions leave important questions about the geographic scope, duration, and mechanics of the incident unanswered.

The distinction matters. Based on the information currently available, this was not described as an attacker breaking into Revolut’s core infrastructure and moving customer funds. Instead, the reported failure occurred in the process used to evaluate and respond to an external request for information. That makes the incident a test of institutional identity verification, authorization controls, and data-minimization practices as much as a conventional cybersecurity event.

Why a legitimate domain is not sufficient proof

Government requests often receive heightened attention inside financial institutions. They may relate to fraud inquiries, law-enforcement investigations, regulatory requests, or urgent efforts to identify account activity. Staff handling those requests may be under pressure to respond quickly, particularly when a message appears to come from an official address.

But a legitimate domain does not, by itself, establish that a request is genuine. It does not prove that the person sending the message is the authorized official, that the request has an appropriate legal basis, or that the requested data is necessary and properly scoped. An attacker may exploit a compromised mailbox, misuse an authorized account, or take advantage of weaknesses in the way an institution validates incoming requests.

The case therefore shifts the security question from simply asking whether an organization’s network was breached to asking how it determines that an external request deserves a response. Email authentication controls can help confirm that a message was sent through an approved domain, but they cannot independently verify the sender’s authority or the legitimacy of the underlying demand.

A stronger process would separate several checks: the identity of the requester, the agency’s involvement, the legal or procedural basis for the request, the specific categories of data sought, and the urgency claimed. Independent confirmation through a known telephone number or a dedicated government channel could provide an additional safeguard for highly sensitive disclosures. A second-person approval process may also be appropriate when a request involves identity documents, account statements, or transaction histories.

The digital-asset privacy dimension

The incident also has implications beyond ordinary digital banking data. The information described in the customer notification may have included transaction histories and Bitcoin activity. The available reports do not establish exactly which transactions were exposed, whether all listed categories applied to every affected customer, or whether any assets were taken. It is therefore important not to conflate data disclosure with a compromise of customer funds.

At the same time, the absence of a funds theft does not make the privacy risk immaterial. A passport copy, verification selfie, contact information, and transaction history can together create a detailed personal and financial profile. For a customer who has used digital-asset services, transaction information may reveal more than a balance or a payment: it may indicate exposure to a particular asset, service, or financial activity. Combined with data from other sources, such records could support targeted phishing, impersonation, or social-engineering attempts.

This distinction is especially relevant for custodial platforms, banks, payment companies, and institutional wallet providers. Security programs commonly focus on protecting private keys, payment approvals, and asset-transfer permissions. Those controls remain essential, but they do not cover every high-impact failure mode. Know-your-customer files, beneficial-owner records, identity documents, transaction-monitoring alerts, and account statements can also become valuable targets even when no asset moves on-chain.

For institutions managing digital-asset operations, the practical lesson is that data-access controls should be designed around the sensitivity of the information, not only around the ability to transfer funds. Permissions should be segmented, access should be logged and reviewed, and external disclosure requests should be evaluated independently of routine account-support workflows. A platform can preserve the integrity of customer balances while still exposing customers to meaningful privacy and identity risks.

The company’s response and the regulatory questions

Revolut said it blocked the email address after identifying the fraudulent activity and alerted the relevant government agency, law-enforcement authorities, and regulators. The company also said that its systems and customer funds were unaffected. It has contacted the customers it considers affected, although the public material does not specify the timing or full content of those communications.

The next phase is likely to focus on how the request entered Revolut’s internal process and what controls were applied before the disclosure occurred. Investigators and regulators may examine who could approve the requests, whether a second verification channel was available, how much data was provided in each response, and whether access and disclosure records were retained. They may also assess the company’s incident-response and customer-notification procedures.

Revolut operates across multiple markets and describes itself as a bank in more than 30 countries. That international footprint may make the compliance context more complex, because data-protection, financial-regulatory, and cybersecurity-reporting requirements can differ by jurisdiction. The available reporting does not establish whether any particular law or rule was violated, and the outcome will depend on the facts developed by the relevant authorities.

For customers who received a notification, two risk questions should be kept separate. The first concerns account and funds security: whether there is evidence of unauthorized access to the account or financial activity. The second concerns information exposure: whether personal documents, contact details, or transaction data may now be in the possession of an unauthorized party. The company’s statement that systems and funds were unaffected addresses the first category, but it does not eliminate the need to evaluate the second.

Moving beyond domain-based verification

The broader industry lesson is not that financial institutions should stop responding to government requests. Legitimate information-sharing between regulated companies and public authorities is an important part of fraud prevention, enforcement, and financial oversight. The lesson is that the source of a message and the authority behind a request must be verified through more than one signal.

Controls could include independent callback procedures, validation of the requester’s role, confirmation of the agency’s case reference, documented review of the legal basis, and approval by more than one employee for high-risk disclosures. Requests should also be limited to the information necessary for the stated purpose. When identity documents, selfies, statements, and digital-asset transaction histories are involved, the threshold for additional review should be correspondingly high.

Automation may help identify unusual language, abnormal request patterns, or access behavior that differs from normal workflows. However, automated detection should support rather than replace human accountability. A clear audit trail is particularly important when staff are asked to act quickly on a request that appears to come from a government body.

The currently public facts establish a limited customer impact, potential exposure of sensitive identity and financial data, and a response that includes customer notifications and reports to authorities. They do not yet establish the full data set obtained by the attacker, whether the information was misused, or how the fraudulent requests bypassed internal checks. Those questions will determine the incident’s ultimate significance.

For digital banks and the wider digital-asset ecosystem, the episode is a reminder that protecting customer funds is only one part of operational security. Identity data and transaction histories require equally disciplined controls. A resilient disclosure process must make every external request verifiable, appropriately scoped, independently reviewable, and traceable after the fact.

Source: link

PAYMENTREGULATIONS

About Cobo

Cobo is an institutional digital asset infrastructure provider founded in 2017. The Cobo Agentic Wallet extends Cobo's MPC custody platform to autonomous onchain agents.

Press inquiries: [email protected] · Media kit, executive bios, and additional materials available on request.
Agentic Economy by Cobo

Get this in your inbox every Friday.

The weekly newsletter from the Cobo team — unpacking the most consequential stories in crypto, AI & payments through the lens of institutional custody.