Revolut is worth $115 billion. That's the number a secondary share sale put on the fintech giant in July 2026, up from $75 billion just eight months earlier (Dealroom). A hundred-and-fifteen-billion-dollar company, more than 65 million customers, biometric-grade identity checks, the whole fortress.
Someone walked past all of it with an email.
On September 12, Revolut confirmed that an attacker impersonated a government agency β using a real, valid government email domain β to file fraudulent requests for customer data. And Revolut answered them. Out went names, dates of birth, home addresses, phone numbers, passport and driver's license copies, KYC verification selfies, account statements with IBANs, withdrawal records, and full transaction histories, Bitcoin activity included (TechCrunch, BleepingComputer).
No malware. No zero-day. No brute-forced password. The exploit was a piece of paperwork that looked official enough to trust. The most dangerous hole in a bank isn't in its code β it's in its inbox.
π§ Why This Matters
Every bank on earth has a process for handing customer data to law enforcement. Police send a request, the bank verifies it's real, the bank complies. It's legally required, it's routine, and it runs on trust that the sender is who they claim to be.
That trust is exactly what got weaponized. In Revolut's own words, the request "came from an unauthorised email account sent directly using the official government agency's email domain," and because "the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request" (BleepingComputer).
"Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government domain email to submit fraudulent requests for information." β Revolut statement
Read that twice. The email passed the technical checks. The domain was legitimate. The controls a company would normally lean on to spot a fake β did the address authenticate? β all said yes, this is fine. The failure wasn't a firewall. It was the assumption that a request wearing a government badge deserves the benefit of the doubt.
π Deep Dive
What makes this breach different from the usual database-dump story is who got hit and how surgically. On-chain investigator ZachXBT reported that the attack appeared aimed at a relatively small number of high-net-worth users β not a smash-and-grab of all 65 million accounts, but a targeted pull (TechCrunch). Former Mt. Gox CEO Mark KarpelΓ¨s publicly confirmed he was among those affected (Protos).
And then there's the ask. Attackers reportedly demanded 10,000 BTC β roughly $780 million β though Revolut has not confirmed any ransom (The Register, Protos).
Here's how the anatomy stacks up against what people picture when they hear "bank hack":
- The weapon: not code β a spoofed-but-authenticated government email. Zero technical intrusion into Revolut's systems.
- The target: not the mass database β a curated set of high-net-worth customers, crypto holders reportedly among them.
- The loot: not passwords β passports, selfies, IBANs, and complete transaction trails, including on-chain Bitcoin history.
- The demand: a reported 10,000 BTC (~$780M) ransom, unconfirmed by the company.
- The damage to funds: Revolut says systems and customer money were unaffected β the theft was information, not cash (BleepingComputer).
Notice the mismatch. The money stayed put. The identities walked out the door. For a wealthy crypto holder, a leaked passport plus a full Bitcoin transaction history is arguably worse than a drained checking account β you can't reissue your face, and you can't un-publish where your coins live.
β οΈ The Catch
Revolut moved fast once it noticed: it blocked the offending address, notified affected customers directly, and alerted the relevant government agency, law enforcement, data-protection authorities, and financial regulators (TechCrunch). All correct moves.
The catch is that none of it un-leaks the data. A passport scan and a KYC selfie are permanent β they don't expire when you change a password, and they're precisely the documents you'd use to pass the next identity check somewhere else. Combine that with a home address, phone number, and a ledger of exactly how much Bitcoin someone moves, and you've assembled the starter kit for phishing, SIM-swaps, extortion, and old-fashioned physical risk.
There's a second catch, quieter but bigger: this wasn't really a Revolut bug. The government-request pipeline is industry-wide plumbing. Any institution that honors law-enforcement data requests β which is all of them β runs on the same trust that just got exploited. Revolut is the name in the headline, but the vulnerability is the whole system's.
π― What Happens Next
Expect three moves. First, verification of "legitimate" requests gets a lot less polite β banks will start demanding out-of-band confirmation (call the agency back on a known number) rather than trusting a well-authenticated inbound email. Second, regulators in the EU and UK will circle; a breach touching passports and financial records is exactly what GDPR-era data-protection authorities are built to scrutinize. Third, watch for copycats. A technique this cheap and this effective doesn't stay in one attacker's hands.
Revolut, for its part, still isn't putting a number on how many customers were hit β only that it was "very limited." For context, its previous breach, back in 2022, exposed data on roughly 50,000 customers (BleepingComputer). "Limited" can still be a lot of very valuable people.
π§© Bigger Picture
We spend fortunes hardening the technical perimeter β encryption, biometrics, fraud models humming over every transaction. Revolut had all of that, and it worked: the systems held, the money never moved. The breach happened in the human-and-legal layer, the part where a company decides whom to trust and why.
That layer has almost no encryption on it. It runs on norms β on the shared assumption that a message from a government domain is a message from the government. As identity documents pile up in more databases and attackers get better at wearing borrowed authority, that assumption is turning into the softest target in finance. You can patch a server. You can't patch a reasonable belief.
The strongest lock in the building didn't fail. Someone just knocked, said they were the police, and got buzzed in.
Sources
- TechCrunch β Revolut confirms customer data breach through fake government requests
- BleepingComputer β Revolut discloses data breach exposing financial info, passports
- The Register β Revolut falls for fake government requests, hands over customer data
- Protos β What we know about the Revolut customer data leak
- Dealroom β Revolut's valuation jumps to $115B in secondary sale