Revolut disclosed customer records after fraudulent government data request
Reports say an unauthorised requester used a legitimate government email domain to obtain identity and transaction records, exposing a verification weakness rather than a breach of customer accounts.
Official-looking request passed verification
Revolut disclosed records belonging to a limited number of customers after accepting a fraudulent information request that appeared to come from a government agency, according to reports published by Meduza and TV Rain on September 13. The sender reportedly operated through an authentic government email domain, allowing standard email-authentication checks to treat the message as legitimate.
The material reportedly included identity documents, verification photographs, contact information, account identifiers and some transaction records, including Bitcoin activity. Revolut said customer funds, passcodes and login credentials were not compromised. The company has not publicly identified the government body, the number of affected customers or the date on which the records were released.
A process failure rather than a system intrusion
The distinction matters: available reporting does not describe an attacker entering Revolut’s banking infrastructure or customer accounts. Instead, it describes an external impersonation that defeated the company’s procedure for validating official demands. Email-domain authentication can establish where a message originated, but it cannot by itself prove that the sender is authorised to request a particular customer’s records.
Revolut reportedly blocked the sender after discovering the problem, notified the affected government agency and contacted police, financial supervisors and data-protection authorities. It also began informing affected customers. Those steps establish a response, but they do not yet answer how the request passed legal review, whether the government mailbox was compromised or whether the disclosed data has been misused.
Why regulators will scrutinise the incident
European rules require financial institutions to protect personal information while cooperating with lawful supervisory and law-enforcement requests. A 2026 European Central Bank decision sets formal requirements for processing personal data in prudential supervision. It does not adjudicate this incident, but it illustrates the regulated environment in which banks must verify authority, purpose and proportionality before transmitting sensitive records.
The decisive next evidence will come from a named regulator, a police finding or a detailed Revolut incident report. Investigators will need to determine who controlled the government mailbox and whether other companies received similar demands. Until then, the scale and downstream harm remain uncertain. This is a cybersecurity and regulatory story, not a military-alert candidate.