How a Real Government Email Fooled Revolut: Business Email Compromise Explained
If you have learned how hackers attack, break into systems, and gain access in our other articles, you probably already know the attack methods attackers use.
But the Revolut case is different. Nobody broke in.
The attacker simply asked for the data and got it. Yes, you read it right. Let’s break down what happened.
What happened at Revolut?
In September 2026, British fintech company Revolut confirmed that it disclosed sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
This was not a fake address made to look official. The email came from a real government domain, but from an unauthorized account with valid domain authentication credentials, so Revolut believed it was sending the information to a genuine agency.
The story became public when crypto investigator ZachXBT flagged the customer notification on 12 September.
Revolut described it as a sophisticated impersonation scam. It did not publicly name the government domain involved, though alleged extortion images posted on Telegram by an account claiming responsibility suggest the email came from an Italian domain.
What data was exposed?
According to emails sent to affected customers, the exposed information included birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports, driver’s licenses and facial verification images.
It went further. The notice said account statements, IBANs, withdrawal records and full transaction histories, including Bitcoin activity, may also have been shared.
In short, the attacker received a complete identity kit.

There is some good news. Revolut says passwords, card PINs and crypto private keys were not disclosed, and no customer funds have been reported missing.
Who was targeted?
The attackers appear to have gone after high-net-worth individuals, many of them involved in crypto asset businesses.
Why them? Because a wealthy crypto holder with a known address and a passport copy is a perfect target. For extortion. For SIM swaps. For convincing follow-up scams.
Revolut said only a limited number of customers were affected and that it had notified them directly.
What is Business Email Compromise?
Business Email Compromise, or BEC, is a scam where the attacker uses a trusted email identity to trick an organization into doing something harmful.
Usually that means sending money. Sometimes, like here, it means sending data.
If this sounds a lot like phishing, that’s because it is. BEC is phishing’s more patient cousin. Instead of sending thousands of emails and hoping someone clicks, the attacker sends one carefully written message to the right person.
In our post on what phishing is, we covered the usual warning signs: a strange sender, spelling mistakes, a link that doesn’t match. The Revolut attack had none of them. That’s what makes it so dangerous.
Most BEC attacks rely on a fake address. Something like gov-agency-mail.com instead of the real one. Careful staff can spot that.
The Revolut attack skipped that weakness completely.
The address was real. The domain belonged to an actual government agency.
The authentication was valid. Email security checks passed because the message genuinely came from that domain.
The request looked urgent. Emergency data requests are designed for life-or-death situations, so companies are under pressure to respond quickly.
Once all three line up, the usual warning signs disappear.

Is this a new trick?
No. And that is the uncomfortable part.
Security researcher Brian Krebs documented criminals spoofing government legal requests as far back as 2022, and the tactic was used by the Lapsus$ group.
The FBI also warned in November 2024 that compromised government email accounts were being sold and used for fraudulent emergency data requests.
So the warning was out there. The Revolut case shows how hard it is to act on it.
It’s also worth noticing what the attacker didn’t need. No malware. No stolen passwords. No zero-day exploit. Attackers pay huge sums for zero-days because they can break into systems no one knows are weak. This attacker skipped all of that. All it took was one hijacked email account and a convincing request.
Why did it work?
Because the weak point was not technology. It was trust.
We see this pattern again and again. In how cyberattacks work, we explained that attackers rarely start with the hardest target. They look for the easiest way in. Often that’s a person, not a system.
Unlike a typical cyberattack, this incident didn’t require special tools or technical knowledge to break into Revolut’s systems. Instead, they exploited the trust companies place in official government communications.
Think about it from the employee’s side. An email arrives from a real police or government domain. It passes every check. It says someone is in danger.
Would you say no?
That is exactly the pressure attackers count on.
What did Revolut do after?
Revolut said that once it detected the scam, it immediately blocked the address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators.
Still, questions remain. It is not known whether the same compromised domain was used against other financial organizations.
How can organizations stop this?
Here is the hard truth. A real domain no longer proves a real request.
So the checks have to go deeper than the email address. Here is what needs to change.
Call back through a known channel. Never trust the phone number or contact details inside the request itself. The attacker wrote those. Go to the agency’s official website, find their published number, and call them yourself. For legal requests, confirm them only through proper legal channels.
Limit who can release full records. A full KYC file holds someone’s whole identity, so one person shouldn’t be able to send it out alone. Have a second person sign off first. It only adds a few minutes, and a fresh pair of eyes will often spot what the first person missed.
Share the minimum. Before sending anything, look at the request and ask yourself if it makes sense. Say the police are searching for a missing person. They might need a phone number or the last address you have on file. That’s usually it. Why would they need a passport scan, a selfie, and two years of bank statements for that? When a request asks for everything at once, something is off. Slow down and find out who’s really on the other end.
Log and review every release. Every data release should leave a trail. If something looks unusual, like several high-value customers in one week, stop and take a second look.
What should customers do?
If you received a notice from Revolut, don’t panic. But do stay alert.
Your data is now in the wrong hands. Here is how to protect yourself.
Expect scam calls and messages. Criminals will use your real details to sound convincing. They may know your name, address, and even your recent transactions. That does not make them genuine.
Never share one-time passwords or login details. A real bank will never ask for them. Not by phone, not by email, not by text.
Watch for SIM-swap signs. Leaked personal details are exactly what SIM swappers need. The fraudster uses your details to pose as you, then convinces your mobile provider to move your number to their SIM, usually by claiming they lost their phone. Once that happens, your phone loses its connection, and every text and call, including one-time passwords, goes to the attacker instead. If your phone suddenly loses signal for no clear reason, call your provider right away.
Lock down your crypto. If you hold crypto, this part is for you. The attackers chose crypto holders on purpose. Once crypto is sent, it’s almost impossible to get back. So take ten minutes today and log in to every exchange and wallet you use. Turn on two-factor authentication with an authenticator app instead of text messages. After what we just covered about SIM swaps, you can see why. Then look at your withdrawal settings. If your exchange lets you whitelist addresses or add a delay before withdrawals, switch it on. If someone ever gets in, those small speed bumps could save your funds.
Final thoughts
The Revolut case teaches a hard lesson.
Security checks can pass. Domains can be real. And the attack can still be fake.
The next wave of BEC will not always look suspicious. Sometimes it will look perfectly official. The only real defense is a process that verifies before it trusts.
In a future post, we will look closer at emergency data requests and why they have become a favorite tool for attackers.