Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks
Brief
Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks.
Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s domain infrastructure. TechCrunch reported .
The customer notification, which began circulating on September 11, stated that the communication carried valid domain authentication credentials, meaning the email passed the checks that are supposed to confirm a message genuinely comes from a government authority.
“Revolut received a request for customer information that appeared to come from a legitimate government agency.
