Revolut Confirms Customer Data Breach After Falling for Spoofed Government Requests

British fintech Revolut confirmed it disclosed sensitive customer data — including birth dates, addresses, phone numbers, and copies of passports and driver’s licenses — to an unauthorized third party, TechCrunch and Reuters reported. The attacker spoofed a legitimate government agency’s email domain, passing SPF, DKIM and DMARC authentication checks, to submit fraudulent information requests that Revolut’s process treated as genuine.

Revolut said customer funds and core systems were unaffected, and it has notified regulators and law enforcement.

Why it matters: The breach illustrates a persistent weak point in data-request handling processes: even well-implemented email authentication (SPF/DKIM/DMARC) does not by itself verify that a request is legitimate if an attacker can obtain or spoof a domain that passes those technical checks, meaning verification of the requester’s actual authority remains a human-process problem, not just a technical one.

Source: TechCrunch and Reuters, September 12, 2026.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *