By Isaac • September 12, 2026 2:39 pm •
Revolut sent a package of sensitive customer information to an unauthorized third party after treating a fraudulent government request as legitimate.
The exposed material went far beyond an email address or account number. Affected customers were told it could include identity documents, verification selfies, home addresses, account statements, wallet reference numbers and complete transaction histories—including Bitcoin activity.
Trending: Hackers just breached this top login protection service. Here’s what to do
CryptoSlate reports that the request came from an unauthorized mailbox created inside a real government agency’s domain infrastructure. The message carried valid domain-authentication credentials, which made it look substantially more convincing than an ordinary spoofed email.
Revolut fulfilled the request under the belief that it came from the agency. The company later contacted that agency to verify the request,
Continue reading
Join the conversation!
Please share your thoughts about this article below. We value your opinions, and would love to see you add to the discussion!