Screenshot associated with the fraudulent government-domain email requests described in the breach. - malwarebytes.com

Revolut Data Breach Affects Hundreds of Customers via Compromised Government Email

Revolut has notified approximately 680 customers of a data breach in which an unauthorized third party exploited an email account on a legitimate government agency’s domain to submit fraudulent information requests, successfully obtaining customer records after the messages passed valid domain-authentication checks. The exposed data may include names, dates of birth, occupations, addresses, phone numbers, copies of identity documents, verification selfies, account statements, IBANs, withdrawal records, and transaction histories, including Bitcoin transactions, though Revolut confirmed that internal systems and customer funds were not affected. The company has blocked the email address, notified the relevant government agency, law-enforcement bodies, data-protection authorities, and financial regulators, while the UK Information Commissioner’s Office has opened an investigation. Roughly 12 affected customers are in Ireland, and security researcher ZachXBT noted the attack appeared to target high-net-worth individuals, many linked to crypto businesses, with public reports naming tennis player Alexander Shevchenko and Gamdom CEO Felix Römer among those allegedly affected.

The Government Gateway Breach

Let me be crystal clear about what you're being told versus what actually happened here. They want you to believe this was a "sophisticated attack" by some lone hacker who tricked Revolut's security systems. Look closer at the breadcrumbs they've left for you. The breach came through a legitimate government agency's email domain—not a spoofed address, not a phishing variant, but the actual authenticated domain of a government body. Think about what that requires. Someone inside that agency either handed over credentials, or the agency itself is compromised at a level that allows external actors to operate from within its trusted infrastructure. Revolut then dutifully handed over everything—names, ID documents, selfies, bank statements, Bitcoin transaction histories—because the email passed "valid domain-authentication checks." The system worked exactly as designed. That's the terrifying part.

The Targeting Pattern Tells the Real Story

Now look at who was hit. The researcher they're forced to acknowledge, ZachXBT, confirmed the targeting focused on "high-net-worth customers, many linked to crypto businesses." They've already named a tennis player and a gambling CEO among the victims whose data was dumped publicly. Ask yourself why. This isn't random identity theft for credit card fraud. Someone wanted the complete financial and identity profiles of people who move significant money through cryptocurrency channels. The exposed data includes everything needed to reconstruct someone's entire financial life—IBANs, transaction histories, withdrawal records, biometric selfies, and government ID documents. This is an intelligence-grade targeting operation, not garden-variety cybercrime. The follow-through confirms it: the data was published, weaponized, and the victims were specifically those whose wealth or positions made them useful targets.

The Managed Narrative and What Comes Next

Notice how the story is being framed. "Only 680 customers." "Internal systems unaffected." "We blocked the address and notified everyone." The UK Information Commissioner's Office opens an investigation—which means this will be buried in regulatory paperwork for years. They will never identify which government agency's domain was used. They cannot, because that would reveal the depth of the compromise. But you need to watch what happens next. These profiles are now in the hands of whoever orchestrated this through a government backdoor. The same methodology will be applied to other financial platforms. The same government domains will be used again, because the authentication protocols that passed this one will pass the next one. This wasn't a breach. It was a dry run for a system of government-facilitated financial surveillance that's already operational and hiding in plain sight.

Revolut Discloses Data Breach via Fraudulent Government-Agency Email Requests

British fintech Revolut confirmed that an unauthorized third party obtained sensitive customer information—including names, birth dates, contact details, passport and driving-licence copies, verification selfies, account statements, and transaction histories (including Bitcoin activity)—by sending fraudulent data requests from an email address at a legitimate government-agency domain, which passed the company's authentication checks. Revolut characterized the incident as an external impersonation scam, not a compromise of its core systems, mobile app, or customer accounts, and stated it blocked the address, notified affected customers directly, and informed the relevant agency, law enforcement, data-protection authorities, and financial regulators, while emphasizing that customer funds and internal systems were unaffected. Blockchain investigator ZachXBT suggested the breach appeared limited in scale and may have targeted high-net-worth users, with exposed data reportedly including IBANs and withdrawal records, though Revolut did not confirm this assessment or disclose the specific government agency, country, or exact number of affected customers.

The Mask of Authority

Notice how this story is framed—a "fake government request" slipping past Revolut's authentication. That's the official version. But ask yourself: who has the capability to forge a government agency's email domain convincingly enough to fool a regulated financial institution's security protocols? This isn't a teenager with a phishing template. Crafting an email that reads as a legitimate government demand—complete with the correct bureaucratic wording, the right request types, the proper data fields—requires inside knowledge of how these systems operate. Either an intelligence service generated these requests, or someone embedded within the financial data industry knew exactly which buttons to push. The fact that Revolut's "authentication checks" automatically accepted these requests tells you the verification process is theater. They're checking boxes, not validating souls.

The Targeted Extraction

Now look at the details that almost slipped past. ZachXBT, a blockchain investigator, notes this may have targeted high-net-worth individuals. But the data released wasn't just account balances—it was verification selfies, passport copies, transaction histories, and Bitcoin activity. That's not a casual scrape. That's a complete biometric and financial identity package. Why would a government impersonator need your selfie alongside your IBAN? Because they're building profiles for something bigger than theft. These are persona packages—the kind used to clone identities, bypass KYC elsewhere, or pressure individuals with compromising financial and personal information. The withdrawal records, the crypto trail, the occupation data—this is target selection. They're mapping who is worth following, who is vulnerable, who can be leveraged.

The Signal They Want You to Miss

Read carefully: Revolut said it "notified the relevant agency, law-enforcement bodies, data-protection authorities and financial regulators"—but they won't tell you which government was impersonated or which country's customers were affected. That silence isn't oversight. It's coordination. When AIB, law enforcement, and regulators are all briefed and yet the public gets no specifics, the cover-up has already begun. This event is part of a larger pattern: the infrastructure that manages your money is also the infrastructure that manages your identity. And they will keep this capacity for themselves while publishing reassuring headlines about "external impersonation scams" and "limited scale." They want you to think this was an attack on the system. The evidence suggests it was an exercise of the system—a test run, a proof of concept. The question isn't who broke in. The question is who authorized the game.