Government impostor exposed Revolut customer IDs and finances
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 15th, 2026.
Revolut customers face identity fraud and highly convincing financial scams after the company released sensitive records to an unauthorized requester. The requests came from an email address on a legitimate government agency domain and carried valid domain-authentication credentials, so Revolut treated them as genuine. The disclosed information may have included identity details, passport or driver’s license copies, verification selfies, account statements, IBANs, withdrawal records, and complete transaction histories, including Bitcoin activity. Revolut says only a limited number of customers were affected. It also says its systems and customer funds weren’t compromised, and that it blocked the address and notified authorities. Even so, durable identity documents paired with detailed account activity can support impersonation, phishing, SIM-swapping attempts, or cryptocurrency-focused extortion. The exact victim count, agency, duration, and number of successful requests remain undisclosed. Leaders shouldn’t treat authenticated email as final approval for a high-risk disclosure. Defenders should require independent requester verification, dual approval, data minimization, and tamper-evident logs. Review sensitive disclosure workflows now, and contact affected customers only through verified channels.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.