Revolut did not lose a perimeter fight. It lost a workflow fight.
On September 14 The Register reported that British fintech Revolut exposed sensitive customer information after falling for fraudulent requests sent from a legitimate government agency’s email domain. Revolut confirmed the attack to The Register but did not specify how many customers were affected. Sources close to the fintech said only a small proportion of customers were impacted. Victim tally: Undisclosed.
Security Affairs, citing customer notifications and TechCrunch’s review, laid out what “fulfilled under the reasonable belief that it was an authentic government agency request” meant in practice. The request came from an unauthorised email account sent directly using the official government agency’s email domain. Because the communication carried valid domain authentication credentials, Revolut treated it as genuine. That is SPF/DKIM/DMARC theater winning the argument that should have required out-of-band verification first.
Data types in the notices, as summarized by Security Affairs and The Register: identity and contact details (full name, date of birth, occupation, postal and email addresses, phone numbers); copies of identity documents (passport and/or driver’s licence); facial verification images (the selfie provided for verification — Revolut said no biometric facial telemetry was involved); account statements including IBAN, account status, opening date, wallet reference number; withdrawal records; and full transaction history, including Bitcoin transactions. ZachXBT shared customer notifications that began circulating around September 11. Treat those as the public record of what customers were told — not as a forensic count.
What this is not: malware on Revolut servers, a remote code exploit, or a funds drain. Revolut’s spokesperson told The Register the company “recently identified a sophisticated external impersonation scam,” blocked the address, alerted the relevant government agency plus enforcement, data protection, and financial regulators, and said systems and customer funds are unaffected. It contacted the limited number of impacted individuals. The company did not name the government agency. That silence matters: peers cannot search their own legal-request logs for the same mailbox.
Threat-actor color on Telegram, as seen by The Register: snippets that appear to belong to high-profile individuals; threats to release “more and more data every day until Revolut pays”; a demand of 10,000 Bitcoin, which The Register equated to more than $782 million. Revolut did not comment on the alleged ransom when asked. CyberMerge labels those figures as actor claims until a company or law-enforcement confirmation lands.
Context that is public and company-adjacent: Revolut serves more than 80 million personal customers globally and more than 800,000 businesses (The Register). Co-founder and CEO Nik Storonsky has hinted at taking the fintech public, but not before 2028, with a target valuation of around $200 billion — a company hint, not a priced IPO. Security Affairs notes conditional U.S. national-bank approval and regulatory-credibility pressure as the backdrop. None of that converts an Undisclosed victim count into a known one.
POV: email authentication proves the message came from a domain. It does not prove the request was authorized by the agency, scoped correctly, or reviewed by a human who called the agency back before shipping KYC packages. Legal-request workflows are now a control plane. Attackers who can create or compromise a mailbox inside a government domain do not need to breach the bank. Question every fintech and broker that still treats “valid SPF from .gov” as a green light. Sources: The Register Sep 14 and Security Affairs Sep 12. Count stays Undisclosed.
Underwrite sheet — sourced only: fraudulent requests from a genuine government agency email domain; valid domain authentication; limited customers impacted (company); systems and funds unaffected (company); data types per notices (ID docs, selfie without biometric telemetry, DOB/contact, statements/IBAN, withdrawals, full tx history incl. Bitcoin); agency unnamed; actor ransom claim 10,000 BTC / >$782M (Register; unverified by Revolut); 80M+ personal / 800k+ business customers (Register). The process failed. Headcount: Undisclosed.
