Revolut Handed Customer Passports to a Fake Government Request. The Email Was Real.


Revolut has more than 80 million customers and a security team most businesses can only dream of. Last week it confirmed that it handed passports, driver's licenses, facial verification selfies, bank account numbers, and complete transaction histories for some of those customers to an impostor. Nobody hacked in. Someone asked, and the email looked right.
What Revolut has confirmed
In a statement reported by TechCrunch on September 12, Revolut said it "recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests." The company says it blocked the address as soon as it detected the scam and alerted the government agency involved, law enforcement, data protection authorities, and financial regulators. Its systems were not breached and customer funds were not touched.
The customer notification, quoted by CyberInsider, lists what went out: full names, dates of birth, occupations, postal and email addresses, phone numbers, copies of identity documents, the selfies used for identity verification, IBANs, account opening dates, wallet references, withdrawal records, and full transaction histories. Revolut describes the affected group as "very limited" and has not published a number. It has not named the agency that was impersonated, and it has not said how the attacker came to be sending from that agency's real domain. The incident was first surfaced publicly by the crypto researcher ZachXBT, who suggested it looked aimed at high-net-worth customers.
The sentence that should worry every business owner
Buried in the notification is the line that matters. The fraudulent requests, Revolut told customers, "passed the technical checks normally associated with that agency's email domain."
Read that again. This was not a lookalike domain with a swapped letter. It was not a free webmail address pretending to be official. The mail came from the agency's actual domain. Revolut did not spell out which checks it meant, though IT Pro reported the messages carried valid domain-authentication credentials, and the standard ones are SPF, DKIM, and DMARC, the records that confirm a message really was sent from the domain it claims. Awareness training that stops at "check the sender's address" would have passed this email.
That is the trap. Sender authentication proves that a message came from a mailbox on that domain. It says nothing about whether the person using the mailbox is who they say they are or wants what they say they want. A real account in the wrong hands passes the domain checks, because technically, it is real.
This is a known playbook, and the FBI called it
In November 2024 the FBI issued an industry notification about exactly this. Its wording: "Cybercriminals are likely gaining access to compromised US and foreign government email addresses and using them to conduct fraudulent emergency data requests to US based companies, exposing the personal information of customers to further use for criminal purposes."
The FBI described a market, not a one-off, listing six dated examples between August 2023 and August 2024. In August 2024 a criminal on a cybercrime forum offered "High Quality .gov emails" for espionage, social engineering, extortion, and data requests. Five months earlier another actor claimed to own government email accounts from over 25 countries, usable for fake subpoenas. The FBI's advice to companies receiving such requests was to scrutinize doctored signatures and logos, to verify that the legal codes cited match what the originating authority would actually use, and, where validation is needed, to contact the originating authority directly.
Revolut has not said its case was a compromised account bought on a forum. But a compromised account is the mechanism the FBI described, and it is the simplest explanation for mail arriving from a real government domain.
The warning did not slow the trend. In the FBI's Internet Crime Complaint Center report for 2025, government impersonation complaints nearly doubled from the year before: 32,424 complaints and just under $798 million in reported losses, up from 17,367 complaints and about $406 million in 2024. Business email compromise, the category that vendor and invoice fraud fall under, accounted for more than $3 billion in reported losses in 2025 on its own. Revolut is the newest headline in a line that was already climbing.
You are not Revolut. You get the same lever in a different costume.
A criminal impersonating a government agency to a fintech is asking for customer files. The same criminal, aimed at a 10 to 500 person business, asks for something else. The costume changes. The lever does not: authority plus urgency, delivered through a channel you are inclined to trust.
Your version looks like a message from "the IRS" about a payroll discrepancy. A "fraud desk" at your bank that needs you to confirm account details today. A law firm with a subpoena and a deadline. Your largest customer's accounts payable department asking for W-9 and banking information. Your longest-standing vendor letting you know their remittance details have changed, sent from the vendor's real mailbox after someone phished their bookkeeper. That last one is vendor email compromise, and it is the same mechanism as the Revolut incident with the government replaced by a supplier: a real account, in the wrong hands, asking for something plausible.
We wrote recently about phishing that waits for you to finish MFA and then walks in. This is the same lesson from a different direction: the attacks that work in 2026 are the ones designed to pass the check you were taught to rely on.
The one rule, and the layers around it
The most reliable control against this kind of request is not technical. It is a rule: any request for sensitive data, credentials, or a change to where money goes gets verified through a second channel before anyone acts on it. Call the requester back on a number you already have or can find on their official website, never a number in the email. Put it in writing, give it to everyone who can release data or approve a payment, and make it clear that following the rule is never the mistake, even when the request turns out to be real. Revolut has not described its internal review. But an email that passes every technical check gives a reviewer no technical reason to doubt it. A callback supplies one.
Around that rule, three layers earn their keep.
Email security that reads intent, not just headers. Our managed email security is built on Check Point Harmony Email and Collaboration, which Check Point says blocks impersonation, zero-day phishing, and business email compromise using AI-trained engines. Check Point describes the approach as inspecting a message's metadata, links, and language along with the history between sender and receiver to judge whether it is really who it claims to be, not only whether the domain checks out. We will be honest: a request from a genuinely compromised legitimate account is the hardest case for any filter, which is why the verification rule above comes first. But a layer that scores intent has a chance where a layer that only scores the domain has none.
Know when credentials surface. The government mailboxes in the FBI's warning were bought and sold on criminal forums. Your staff's credentials get traded in the same places, and a compromised mailbox at your business is how you become the "real sender" in someone else's incident. Our dark web monitoring add-on watches those markets for credentials tied to your domains so a password can be reset while resetting it still matters.
Someone to call. Every cAIberOps customer gets a named engineer who knows their environment. When an urgent, official-looking request lands and the person holding it is not sure, the engineer is the second channel. That is a large part of what "managed" means.
Revolut will recover from this. It has the lawyers, the regulators' attention, and the budget. A 40-person firm that wires a vendor payment to a criminal's account, or emails its client list to a fake subpoena, often does not get the same runway. The rule costs nothing to adopt. The layers cost far less than one incident typically does.
We work with small and medium businesses nationwide from our home base in McLean, Virginia. If you want to know what an impersonation attempt looks like against your inbox, and whether your current setup would notice, book a free 15-minute call. We will show you what our email layer flags in a typical week for mailboxes like yours.
Sources: Revolut statement and customer notification as reported by TechCrunch (Sept 12, 2026), CyberInsider, IT Pro, and Malwarebytes; FBI Private Industry Notification, "Easy Access to Information for Conducting Fraudulent Emergency Data Requests" (Nov 4, 2024); FBI Internet Crime Complaint Center, 2025 Annual Report.
Comments