Revolut handed customer information to an impostor whose request came from a real government agency’s email domain. In a September 12 statement to The Block, the company confirmed the deception, said it had blocked the sender and contacted affected customers, and said its systems and customer funds were unaffected.[1]
The important distinction is where the trust failed. A customer did not have to type a password into a fake banking page for this kind of disclosure to happen. The company holding the records was persuaded to release them. Protecting an account’s login and protecting copies of its owner’s documents are different jobs.
A genuine domain did not make the request genuine
An email address can look credible because it belongs to a real institution. That establishes a connection to the institution’s mail infrastructure; it does not, by itself, establish that the person sending a particular request has authority to obtain customer records. The dangerous step is turning confidence in the address into permission to disclose the data.
This distinction predates the Revolut case. In November 2024, the FBI warned that criminals were abusing compromised government email accounts for fraudulent emergency data requests. The bureau described how urgency could shorten scrutiny and recommended checking the request’s details and contacting the originating authority when validation was needed.[2] That warning explains a known attack pattern; it does not identify who controlled the mailbox in this incident.
Account access and identity exposure are different problems
The Block’s reporting describes potentially disclosed identity-document copies, verification selfies, contact details and financial records. The affected-customer count and government agency remain undisclosed.[1]
The privacy risk follows from combining records that are usually kept apart. A caller who knows an address or a past payment can sound convincing. Those details are reasons to verify the caller independently, never a reason to supply a login code. This is a possible follow-on abuse, not evidence that every notified customer has already been targeted.
Changing a passcode cannot retrieve an identity-document copy already released. Equally, learning about a data disclosure does not establish that someone can log in to the account. Keep those questions separate when reading a notice or reporting signs of identity theft.
Verify your notice inside the app
Open Revolut yourself and ask support whether your account is affected and which records the notice covers. Its current support instructions are profile icon → Chats → Support. Revolut also says it will not call about a personal account without first alerting the customer through in-app chat.[3] Use that independent channel if an unexpected message offers to “secure” your account.
The lesson applies on both sides of a disclosure: a trusted-looking sender and accurate personal details can support a convincing story. Neither replaces checking that the particular request is legitimate before handing over more information.
References
- Zack Abrams. “Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov’t domain.” The Block, September 12, 2026. Includes Revolut’s direct response. Company response and reported notification.
- Federal Bureau of Investigation. “Easy Access to Information for Conducting Fraudulent Emergency Data Requests Impacts US-Based Companies and Law Enforcement Agencies.” November 4, 2024. FBI notification.
- Revolut. “Contact us.” Accessed September 14, 2026. Official support and call-verification guidance.

