1. Executive summary
Revolut confirmed on Saturday 12 September 2026 that an attacker impersonating a government agency — sending from an email address on that agency's own domain — obtained sensitive customer records, and has notified affected customers directly. Exposed data per Revolut's own notification includes birth dates, postal and email addresses, phone numbers and copies of identity documents (passports, driving licences), with verification selfies, account statements and transaction histories also possibly in scope. No CVSS score, CVE or CISA-KEV entry applies: this is a social-engineering-enabled data disclosure, not a software vulnerability, and no verified reference data was resolved for this item. The bottom-line risk to EMEA financial services is downstream identity fraud and KYC-bypass account takeover using authentic government-issued identity documents, plus the supply-chain lesson that a valid sender domain is not authentication. Attribution is unconfirmed and no threat actor has been named by any source.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| NIS2 Art. 21(2)(d): supply chain security measures | The attacker obtained customer records by impersonating a government agency from a legitimate address on that agency's domain — i.e. the control that failed was trust in an external party's email identity, not a technical compromise | Review supplier and authority identity-verification procedures now: mandate out-of-band callback (known number, not one supplied in the request) before releasing customer data, KYC documents or payment instructions in response to any inbound email; treat domain-valid mail as unauthenticated |
| DORA Art. 28: ICT third-party risk — general principles | Conditional: engaged only if Revolut appears in your ICT third-party provider register or you consume Revolut services (e.g. as a corporate customer, partner or embedded-finance counterparty) | Confirm whether Revolut is a registered ICT third-party provider; if so, request the incident scope and affected-data categories in writing and record the response against your third-party risk file |
No other article in the regulatory reference is directly engaged by this item. DORA Art. 17/18/19 apply to the reporting entity's own incident-management and classification duties and are not triggered by a third party's disclosure; DORA Art. 24 (resilience testing), Art. 29 (concentration risk) and Art. 30 (contractual provisions) are not engaged on the facts available; UK NIS 2018 OES/RDSP duties attach to the affected UK entity, not to EMEA clients reading this note.
3. Technical analysis & attack chain
Confirmed steps, as reported:
- An attacker impersonated a government agency and sent email from an address on that agency's legitimate domain.
- Using that pretext, the attacker obtained sensitive customer records from Revolut.
- Revolut detected the scheme and blocked the sender's address.
- Revolut alerted the government agency concerned, law enforcement, data protection authorities and financial regulators.
- Revolut notified affected customers directly by email; the bank confirmed the incident publicly on Saturday 12 September 2026 and characterised it as limited in the number of customers affected.
Initial access vector. Social engineering via impersonation of a government authority. The distinguishing technical detail is that the sender used an email address on the impersonated agency's own domain — meaning the pretext survived naive domain-reputation and SPF/DKIM-style checks that a defender would normally apply to inbound mail. The source does not state whether the domain was spoofed, compromised, or legitimately held, and does not describe the specific request made of Revolut staff. Do not assume a technical exploit: none is reported.
Exploited component / CVE. None. No product, version, protocol or CVE is implicated in any source. There is no patch to apply for this incident.
Payload, persistence, privilege escalation, command-and-control, lateral movement. None reported. The source describes an external impersonation scam; Revolut's spokesperson stated the company's systems and customer funds were untouched. Any narrative of malware, backdoors or internal lateral movement would be fabrication.
Data access and exfiltration. Per the customer notification: birth dates, postal addresses, email addresses, phone numbers, and copies of identity documents including passports and driving licences. Revolut additionally stated that verification selfies, account statements and transaction histories may also have been disclosed. This is a high-value KYC corpus: an authentic passport or driving-licence image plus matching date of birth and address is sufficient raw material for identity fraud, synthetic-identity creation and impersonation-based account takeover at other institutions.
Observed impact. Direct customer notification by Revolut; regulatory and law-enforcement notification by Revolut; sender address blocked. No customer fund loss is reported.
Caveated / single-sourced material. Crypto investigator ZachXBT publicised the customer notice in a Telegram post and added data categories Revolut's own notification omitted: IBANs, withdrawal records, occupations, and transaction history covering bitcoin. He assessed the incident as limited in scale but targeted at high-net-worth users. These additions and that targeting assessment are single-sourced and not confirmed by Revolut — treat them as unverified until Revolut or a regulator confirms the full data-category list. The "high-net-worth targeting" claim in particular should not drive client segmentation decisions on its own. No actor attribution is offered by any source, and no MITRE ATT&CK profile is available in the verified reference data; attribution is therefore unconfirmed.

4. Mitigation & containment
There is no vulnerable component to patch and no vendor fix to deploy. Actions are process and fraud-controls oriented.
P1 — within 24 hours
- Suspend acceptance of any inbound email request for customer data, KYC documents, or payment/withdrawal changes that relies on sender domain as proof of identity. Route all such requests through an out-of-band callback to a number held independently in your supplier or authority directory.
- Brief fraud, AML and contact-centre teams that authentic identity-document images (passport, driving licence), dates of birth and addresses are now in circulation for an undisclosed number of Revolut customers. Flag identity-verification and account-recovery flows as elevated-risk for the next 90 days.
- If you consume Revolut services or hold Revolut-issued accounts, request the affected-customer scope and confirmed data categories in writing from your relationship contact.
- Add monitoring for account-takeover patterns that lean on identity documents: SIM-swap-adjacent phone-number changes, address changes immediately followed by credential or payee changes, and recovery flows completed with document upload.
P2 — within 72 hours
- Review and rewrite supplier/authority verification procedures so that domain-valid email is explicitly documented as non-authentication. Where a government agency or regulator is impersonated, require the callback to be to a number published on the agency's own site, not one supplied in the request.
- Confirm whether Revolut is recorded in your ICT third-party provider register; if so, log this incident against that entry and assess whether any of your own data or customers are implicated, which would engage your own DORA Art. 17/18/19 incident process.
- Re-check your own outbound exposure: do your staff receive and act on emailed requests for customer records? Test the control, do not assume it.
P3 — within 7 days
- Run a retrospective fraud review over the last 90 days for account openings, recoveries and payee changes that were authorised on the basis of emailed instructions or uploaded identity documents.
- Tabletop the scenario "attacker emails us from a genuine government domain requesting customer records" and record the outcome against your NIS2 Art. 21(2)(d) supply-chain measures.
- Update the third-party risk file with the outcome of any Revolut information request.
5. Indicators of compromise
No atomic indicators of compromise are available in the source material. No hashes, domains, IP addresses, file paths, registry keys, email addresses or malware artefacts are published by any source. The impersonated agency's domain is deliberately not reproduced here — it is a legitimate government domain, not a malicious indicator, and publishing it would be both useless for detection and misleading.
Behavioural indicators:
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Inbound email claiming to be from a government agency, sent from an address on that agency's legitimate domain, requesting customer records or identity documents | Email gateway logs, mail security platform, staff reports to the security/fraud mailbox | High — described by Revolut and reported by Help Net Security |
| Requests for KYC document copies, verification selfies, account statements or transaction histories arriving by email rather than through an established portal or verified contact | Fraud/AML case management, contact-centre tickets | Medium — the request mechanism is inferred from the disclosed data categories; the source does not describe the specific ask |
| Use of authentic identity-document images plus matching date of birth and address to pass identity verification or account recovery at another institution | Identity-verification vendor logs, onboarding and recovery workflows | Medium — downstream risk, not an observed behaviour in this incident |
| Bulk access to customer records by an account or process not normally associated with that access | Revolut-side only; not observable by third parties | Low — no access telemetry is published |
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Help Net Security, "What we know about the Revolut data breach so far", https://www.helpnetsecurity.com/2026/09/14/revolut-data-breach-privacy/, 2026-09-14
- TechCrunch — cited within the above as the recipient of Revolut's statement; not independently retrieved for this advisory
- ZachXBT Telegram post — cited within the above as the publisher of the customer notice and of additional data categories; not independently retrieved for this advisory
8. Adverse Trace position
No CVSS score, severity rating or CISA-KEV exploitation state is available for this item — the verified reference data resolved nothing, and we will not manufacture a score for a social-engineering data disclosure that has no CVE. Our assessment is that the incident is low in technical sophistication and high in downstream fraud utility: the attacker needed no exploit, only a convincing sender domain, and walked away with identity documents that retain value for years. Client impact is concentrated in identity fraud, KYC bypass and impersonation-driven account takeover rather than any direct compromise of client infrastructure, and the single most transferable lesson is that domain-valid email must never be treated as authentication for requests touching customer data. We flag explicitly that the additional data categories (IBANs, withdrawal records, occupations, bitcoin transaction history) and the high-net-worth targeting claim are single-sourced to ZachXBT and unconfirmed by Revolut — verify before acting on them. We will monitor for regulator confirmation of the full data-category list, for any actor claim or attribution, and for evidence of the exposed documents appearing in fraud or dark-web channels, and will reissue if the scope materially changes.
Published via PulseTrace — Adverse Trace threat intelligence.