Revolut, the British fintech company eyeing a $200 billion valuation and a banking license, just gave away sensitive customer data to someone pretending to be a government official. The attacker didn’t need to hack a single system. They just sent a convincing email.
The incident, which Revolut characterized as a “sophisticated external impersonation scam,” resulted in the exposure of identity documents, verification selfies, full names, dates of birth, contact information, financial records including IBANs, withdrawal histories, and notably, Bitcoin-related transaction activity. Customer notifications began going out on September 11, 2026.
How a fake email passed every security check
The attack worked because the fraudulent data request appeared to come from a legitimate government agency’s email domain. More critically, the message passed SPF, DKIM, and DMARC checks, the trio of email authentication protocols that organizations rely on to verify a sender’s identity.
Think of those protocols as the digital equivalent of checking someone’s ID at the door. SPF confirms the email came from an authorized server. DKIM verifies the message wasn’t tampered with in transit. DMARC ties them together and tells the recipient what to do if either check fails. All three gave the green light on this one.











