No one broke into Revolut's servers. No malware was deployed, no passwords were stolen, and no database was breached. What happened on September 11, 2026 was somewhat simpler: someone sent an email, and Revolut complied.
The fintech giant admitted that it had transmitted sensitive customer files to an unauthorized third party when it received what appeared to be a legitimate government data request. The email spoofed an authentic domain name from a government agency, passing Revolut's authentication checks and triggering the transfer of the data.
Only after contacting the agency through a secondary channel did Revolut become aware of what had happened — the request had apparently been processed automatically under its established procedures.
The volume and sensitivity of the data were significant. It included KYC selfies, photos uploaded during registration, passport and driving license copies, full names, physical addresses, phone numbers, dates of birth, bank statements, and, in some cases, complete transaction histories for users’ Bitcoin holdings. Given the scale of the leak, the case may cast a shadow over the rumored Revolut IPO.
Revolut confirmed to BeInCrypto that this 'sophisticated spoofing cyber-attack where an unauthorized party used a real email domain of a government to file for fraudulent data requests' didn't directly affect customer accounts.
However, a person's full name, physical address, face, and Bitcoin transaction history, combined, create a near-complete profile, sufficient for targeted phishing scams, identity theft, or physical extortion (as in a wrench attack: you don't need to brute-force a wallet if you already know the target's full name, where they live, and what they possess).
Attackers may have specifically been after customers' Bitcoin wallet information. This could be explained by the renewed growth of BTCUSD in recent weeks and the new hacking capabilities enabled by artificial intelligence.

This event also appears to have specifically targeted wealthy users located in France and Belgium, suggesting this was not a mass, untargeted attack but a meticulously planned one.
ZachXBT, an on-chain investigator well-known for his tracking of stolen digital assets, first flagged the incident. Revolut subsequently confirmed the details soon after and blocked the sender once the nature of the compromise had been determined.
The key takeaway from the incident is how it happened: through compliance. The very procedure businesses use to cooperate with lawful government requests became, this time, the entry point for the attack.
This attack did not require hacking skills on the part of the fraudster; it only required the ability to send an email spoofing a legitimate domain name — and an institution's automated systems to handle it.
There was no need to breach firewalls, hack databases, or bypass encryption; internal compliance procedures were exploited instead, and access was simply granted from within.
This appears to be a notable gap in procedure. Usually, institutions maintain a secondary authentication protocol to verify sensitive data requests, such as a callback to the relevant government agency, or manual approval from a compliance officer.
Whether Revolut lacked such requirements or didn't employ them for the request in question cannot currently be confirmed. The company has offered no information regarding how this specific request was handled or how it evaded a higher level of security scrutiny.
According to GDPR regulations, which apply to Revolut's customers residing in France and Belgium, Revolut had 72 hours from discovering the data compromise to report it to relevant national authorities. Whether it met that deadline has not been confirmed either. Depending on the legal assessment of Revolut's procedural failure, a penalty or fine might still follow.
AI involvement is also a significant factor to consider in the nature of this attack. Crafting an emergency data request that realistically appears to originate from a government agency is precisely the kind of task that generative AI tools excel at.
If that's what happened here, institutions accepting legitimate governmental data requests will have to be more rigorous than ever with verification procedures — spoofed messages can and will only become more convincing in the future.
Revolut manages the sensitive biometric and financial data of more than 50 million users in 38 countries. While this breach was confined, the procedural lapse that allowed it will surely need to be addressed institution-wide.