Security News

Revolut Tricked Into Leaking Customer Data via Fake Government Email Request

The Record · 14 Sept 2026
Key Takeaway Businesses should independently verify any urgent data requests claiming to come from government or law enforcement contacts, especially when they arrive via email, before releasing customer information.

Revolut has confirmed that fraudsters impersonating a legitimate government agency were able to obtain sensitive customer data by submitting fraudulent "emergency data requests" from what appeared to be a genuine government email domain. The company says a limited number of customers were affected, and those individuals, reportedly high-net-worth people involved in crypto asset businesses, have been notified directly.

Revolut has not named the government domain involved, though leaked material shared on Telegram by a group claiming responsibility suggested it originated from an Italian government address. Italian authorities have not responded to requests for comment, and the Telegram account has since been suspended, meaning not all details of the claim can be verified. The attackers reportedly demanded an extortion payment from Revolut to prevent further release of customer data, something the company declined to confirm.

Once the fraudulent request was detected, Revolut says it blocked the email address involved and alerted the relevant government agency along with law enforcement, data protection, and financial regulators. It remains unclear whether the same compromised or spoofed domain was used to target other financial institutions.

data breach social engineering fintech security Revolut impersonation scam

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.