Revolut data breach: spoofed government emails bypass authentication
In brief
- Revolut confirmed data breach from spoofed government emails on September 12, bypassing SPF, DKIM, and DMARC checks
- Compromised data included names, birth dates, ID copies, and transaction histories, excluding biometric data
- No customer funds stolen; core banking systems remained secure
- Exact number of affected users undisclosed; reports indicate higher-net-worth individuals targeted
- Second major security incident for Revolut in three years
How the breach occurred
The spoofed messages were good enough to pass SPF, DKIM, and DMARC authentication checks, which are essentially the three-layered security system email servers use to verify that a message actually comes from who it claims to come from. Revolut described the breach as a "sophisticated external impersonation scam." The attackers targeted the company's compliance process itself rather than individual staff credentials, a shift from the 2022 incident that relied on social engineering of employees.
Customer notifications began circulating around September 11, one day before Revolut's public confirmation. The company has not publicly named which government agency was spoofed.
What data was exposed
The compromised data included full names, birth dates, contact information, copies of identification documents, transaction histories, and account statements. Revolut stressed that no biometric facial telemetry data was shared during the incident. The company also maintained that no customer funds were stolen and that its core banking systems were not compromised.
Revolut has not disclosed the exact number of affected users. Reports suggest that a select group of higher-net-worth individuals may have been specifically targeted. On-chain analyst ZachXBT indicated the incident appeared to be limited in scale.
Context and response
This isn't Revolut's first brush with data compromise. The company experienced a breach in 2022 that affected tens of thousands of customers, which involved unauthorized access through social engineering of an employee. The latest incident exposes a different vulnerability: one that exploits email authentication systems and compliance workflows rather than targeting individual staff.
Revolut's response included blocking the fraudulent email address, contacting regulatory bodies and law enforcement, and reaching out to the government agency whose identity was impersonated. The company has been aggressively pursuing expansion across Europe and beyond, and has signaled ambitions toward a public listing—making security incidents of this magnitude particularly sensitive to its growth trajectory.


