Skip to content

Invest1 publisher3 min readPublished

Revolut handed identity files and Bitcoin histories to an email that passed SPF, DKIM and DMARC

The request arrived from what looked like a government agency's domain, cleared all three email authentication checks, and Revolut's compliance team processed it. Notifications to affected customers began on September 11.

The Investor · Invest desk

Photograph accompanying Revolut handed identity files and Bitcoin histories to an email that passed SPF, DKIM and DMARC
Photo: techcrunch.com

What happened

  • Revolut began notifying customers on September 11, 2026 that a party impersonating a government official had obtained their records, in what the company called a sophisticated external impersonation scam.
  • The exposed records included identity documents, verification selfies, names, dates of birth, contact details, IBANs, withdrawal histories and Bitcoin-related transaction activity.
  • The request appeared to come from a legitimate government agency's email domain and passed SPF, DKIM and DMARC, the three protocols organizations use to verify a sender.
  • Revolut's compliance team processed the request and released customer records to an unauthorized third party, who never touched the company's internal systems.
  • Revolut has since blocked the email address and notified law enforcement and regulators. It called the affected population limited and did not give a number.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Email authentication certifies the sending domain and the message. A firm that wants to know a requester is entitled to the data has to add an out-of-band step, and that step is a person making a call by hand.
  • exposure The affected customers now hold a set of attributes they cannot reissue, and a verification selfie paired with an IBAN and a Bitcoin withdrawal history makes a targeting file.
  • decision Supervisors weighing Revolut's banking license now have a named control to test, and Revolut has to choose whether to slow its government-request handling in front of them or defend the workflow as designed.
  • precedent Every regulated firm with a law-enforcement request desk is now dealing with a technique documented as effective against mail that aligns on all three checks, and the cheapest response is a procedural one.

SPF confirms a message came from a server the domain authorized, DKIM confirms nobody altered it in transit, and DMARC ties the two together and tells the recipient what to do if either check fails [6][7][8]. All three passed. Whether the sender was entitled to a customer's identity file is a fourth question, and none of the three checks tests it [16]. The only thing that answers it is an outbound call to a number the agency itself published, which is slow and manual.

Revolut says no passwords, PINs or private keys were compromised and no customer funds moved [9]. What left instead was the onboarding file: the selfie, the date of birth, the IBAN, the withdrawal history [3]. A date of birth cannot be reissued the way a password can.

Cryptobriefing, which reported the notifications, describes no verification step Revolut applied beyond the email checks. It calls the failure a compliance protocol vulnerability: the target was the workflow for answering official government data requests [12].

Revolut is a British fintech eyeing a $200 billion valuation and a banking license [2]. It has been exploring a listing at around that figure, and the license approval turns on scrutiny of exactly these operational controls [13]. The company has not sized remediation spending. The near-term cost is attention: the compliance and legal staff preparing for supervisory review have to document and rebuild a request-handling procedure while the application is live, and they are not spending that time on the application itself.

One version: the affected group really is small, supervisors treat it as one employee's misjudgement, and the license timetable moves as planned. In the second, the count surfaces through customers publishing their notification letters. That is how the incident became public in the first place, including through people known in the crypto industry [11]. And it turns out larger than the word Revolut used. The third and more interesting version is that other regulated firms received the same request from the same domain and have not said so.

I would weight the second and third above the first, because the attack cost one email and touched none of Revolut's internal systems [15], and the counter-measure costs one phone call. A supervisor comparing a cheap attack against a cheap control that was absent is assessing judgement.

I would change my mind if Revolut publishes a customer count in the tens and can show an out-of-band verification step that existed on paper and was skipped by one person. That would make this a staffing failure inside a documented control, and the licensing case weakens considerably. The company described the affected population only as "limited" [10].

What to watch

  • Whether Revolut publishes an affected-customer count, and whether it matches the word "limited" used in the notification letters.
  • Any statement from the regulator handling the banking license application about Revolut's government-request workflow.
  • Whether other regulated firms disclose receiving a request from the same spoofed government domain.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories