Hackers did not need to break into Revolut’s banking infrastructure, defeat its encryption or steal customer passwords.
Instead, they apparently found something potentially even more powerful: a trusted government identity.
Revolut has confirmed that sensitive information belonging to some of its customers was disclosed to an unauthorized third party after the company received fraudulent information requests sent from a legitimate government agency email domain.
The fintech says its internal systems were not compromised and customer funds were not affected.
But that distinction does not make the incident less interesting.
Quite the opposite.
The Revolut breach represents a fascinating example of a growing cybersecurity problem: attackers no longer necessarily need to bypass an organization’s security controls if they can successfully impersonate someone whom the organization is already supposed to trust.
And in this case, the trusted identity appears to have belonged to an Italian government institution.
What happened to Revolut?
On September 12, 2026, Revolut confirmed that it had been targeted by what it described as a sophisticated external impersonation scam.
According to the company, an unauthorized party used an email address belonging to a legitimate government agency domain to submit fraudulent requests for customer information.
Because those requests appeared to originate from a trusted government source, Revolut disclosed information to the attackers.
Reuters independently reported the incident, while the Financial Times later reported that approximately 680 customers had been notified about the breach.
Revolut itself has publicly described the number of affected customers only as limited.
The company said it blocked the email address after discovering the fraud and notified the relevant government agency, law enforcement authorities, data protection regulators and financial supervisors.
What information was exposed?
This was not a breach involving only email addresses or usernames.
According to a breach notification reviewed by TechCrunch, the information potentially disclosed included:
- names and dates of birth;
- postal addresses;
- email addresses;
- telephone numbers;
- passports and driving licences;
- identity verification photographs;
- account information;
- bank statements;
- transaction history.
Some customers may also have had cryptocurrency-related transaction information exposed.
That makes the dataset significantly more dangerous than a conventional marketing database leak.
A combination of identity documents, addresses, financial activity and contact information can potentially be used for highly convincing phishing attacks, identity theft, account recovery fraud and targeted social engineering.
For cryptocurrency holders, there is an additional concern: revealing someone’s identity, home address and financial activity could potentially create physical as well as digital security risks.
The Italian connection
The most intriguing part of the story emerged in Italy.
Italian media reported that the fraudulent communications originated from a compromised institutional email account connected to the country’s public administration.
La Repubblica reported that Revolut received requests from an address using the @pec.interno.it domain, part of the Italian Interior Ministry’s certified email infrastructure.
Other Italian reports have linked the compromised mailbox to the Prefecture of Reggio Calabria, although this specific attribution should still be treated separately from Revolut’s own confirmed statements.
Italian cyber police are investigating the incident for alleged unauthorized access to a computer system and computer fraud.
This distinction matters.
Early descriptions of the incident can easily create the impression that attackers somehow breached the entire infrastructure of the Italian Postal and Communications Police.
There is currently no solid public evidence supporting such a broad conclusion.
What appears to have been compromised was an institutional email identity, and that was enough to make the subsequent requests appear legitimate.
The hackers claim they impersonated Italian law enforcement
According to the Financial Times, individuals claiming responsibility for the attack said they had gained access to an Italian state email system and used it to impersonate law enforcement.
The attackers reportedly submitted repeated information requests over a period of several months.
They claimed that some of their targets were wealthy cryptocurrency users, or so-called “crypto whales.”
The Financial Times reported receiving redacted screenshots that appeared to support parts of the attackers’ account, although claims made by the hackers themselves should naturally be treated with caution.
Most of the affected customers reportedly live in Switzerland and France, with others spread across several European countries.
Why would Revolut provide customer data to the government?
At first glance, one question seems obvious:
Why would a bank send passports, account details and transaction records simply because it received an email?
The answer is that financial institutions routinely receive legitimate requests from law enforcement agencies, regulators, courts and other public authorities.
Revolut’s own privacy policy explicitly states that personal information may be shared with government authorities, law enforcement agencies, tax authorities and fraud-prevention organizations when legally required.
For a global financial institution, responding to lawful requests is therefore not unusual.
It is part of normal regulatory compliance.
And that may be exactly what made the attack possible.
The attackers did not necessarily need to invent an entirely new procedure.
They apparently inserted themselves into an existing and legitimate process.
The email was real. The person behind it wasn’t.
This is the technical detail that makes the Revolut incident particularly important.
There is a major difference between:
forging the identity of a trusted organization
and
taking control of the trusted organization’s real identity.
Traditional email security mechanisms are largely designed to address the first problem.
Technologies such as SPF, DKIM and DMARC help organizations determine whether messages claiming to come from a domain were actually authorized by that domain.
Italy’s certified email system, known as PEC — Posta Elettronica Certificata — adds additional guarantees around the transmission and delivery of messages.
But none of these technologies can completely solve a different problem:
What happens when the legitimate account itself is compromised?
If an attacker controls an authorized mailbox, technical authentication mechanisms may work exactly as intended.
The server is legitimate.
The domain is legitimate.
The mailbox is legitimate.
The cryptographic checks may be legitimate.
Only the human being operating the account is illegitimate.
That is a fundamentally different security problem.
Authentication is not authorization
The Revolut incident highlights a distinction that is sometimes overlooked even in mature security environments.
Authentication answers:
Who is this account?
Authorization answers:
Is this person actually entitled to make this specific request?
And risk verification should add a third question:
Does this request make sense?
A request may therefore be technically authentic while still being malicious.
Imagine an attacker gaining control of a CFO’s corporate email account.
The email itself is genuine.
The company’s domain is genuine.
SPF and DKIM checks pass.
The employee’s mailbox genuinely sent the message.
But if the attacker uses that account to tell the finance department to transfer €2 million to a new bank account, the request is still fraudulent.
The Revolut case appears to apply the same principle at an institutional level.
Instead of compromising a company executive, the attackers allegedly compromised a government identity.
A textbook example of trust abuse
Cybersecurity has traditionally focused heavily on preventing unauthorized access.
Firewalls prevent unwanted connections.
Passwords protect accounts.
Multi-factor authentication makes credential theft harder.
Encryption protects data.
Endpoint security attempts to prevent malware execution.
But attackers increasingly target something more abstract:
trust relationships between organizations.
If Company A automatically trusts requests coming from Organization B, compromising Organization B may indirectly provide access to information held by Company A.
The attacker does not necessarily need to hack Company A at all.
They simply need to become someone Company A already trusts.
This is sometimes far more effective than attacking the final target directly.
Could Revolut have detected the scam?
This is where the incident will probably generate the most debate.
Revolut has a legitimate reason to process law-enforcement requests.
And if an information request arrives through a technically authenticated government communication channel, treating that request as credible is not inherently unreasonable.
But authentication alone should arguably not be the final control when highly sensitive information is involved.
High-risk requests could require out-of-band verification.
For example, rather than verifying a request using contact details contained in the request itself, an institution could independently contact the relevant government agency using previously validated contact information.
The process would essentially become organizational multi-factor authentication.
Factor one:
The request originates from a legitimate government account.
Factor two:
The government agency independently confirms that the request exists.
Additional controls could examine whether the request is unusual compared with historical patterns.
For example:
- Is one government mailbox suddenly requesting dozens of unrelated customers?
- Are the targets located in countries unrelated to the investigation?
- Is the requested dataset unusually broad?
- Has the frequency of requests suddenly increased?
- Are multiple wealthy cryptocurrency users being queried through the same channel?
None of these signals necessarily proves fraud.
Together, however, they can provide the contextual anomaly detection that simple domain authentication cannot.
Revolut was not hacked in the conventional sense
This distinction is important when describing the incident.
There is currently no evidence that attackers compromised Revolut’s core banking infrastructure.
Revolut explicitly says that its systems and customer funds were unaffected.
The data appears instead to have left Revolut through a legitimate business process: responding to government information requests.
Calling the incident simply a “Revolut hack” therefore risks hiding the most interesting part of the story.
The vulnerability was not necessarily a vulnerable web server or an unpatched application.
It was the verification of trust between two organizations.
Why crypto users should pay particular attention
The attackers claiming responsibility have suggested that wealthy cryptocurrency holders were among their targets.
The Financial Times reports that the group specifically referred to some targets as crypto whales.
That raises another security concern.
Cryptocurrency attacks are unusual because stolen information can potentially create physical risks for victims.
If attackers know that a particular individual owns a significant amount of cryptocurrency and also possess that person’s home address, telephone number, identity documents and transaction history, they can build an extremely detailed victim profile.
Information exposure therefore becomes more than a traditional privacy problem.
It can become an operational security problem.
The attackers are reportedly threatening to publish the data
The story may also not be over.
The Financial Times reported that the individuals claiming responsibility were threatening to release the stolen information, while Revolut continued to deal with the consequences of the incident.
Britain’s Information Commissioner’s Office is also investigating after Revolut reported the breach.
Revolut has contacted affected users and says additional security measures have been implemented.
For customers who received a breach notification, however, the most significant risk may now be secondary attacks.
Messages, calls or emails that reference genuine personal information should therefore be treated with particular caution.
The real lesson from the Revolut breach
The Revolut incident illustrates an uncomfortable reality about modern cybersecurity.
We spend enormous amounts of money proving that users, devices and servers are who they claim to be.
But authentication does not automatically prove intent.
A legitimate account can be controlled by an illegitimate person.
A legitimate employee can have a compromised session.
A legitimate computer can run malicious software.
And a legitimate government email account can apparently be used to submit fraudulent requests for customer data.
The security model therefore cannot end with:
“This identity is authentic.”
Organizations increasingly need to ask:
“Is this authentic identity behaving in a way that makes sense?”
That distinction may sound subtle.
In the Revolut case, it appears to have made the difference between protecting customer information and handing it directly to an attacker.
And that may be the most important lesson from this breach:
sometimes hackers do not need to break through your security. They only need to become someone your security already trusts.

