Breaking NewsUpdated as information becomes available
Opinion·Commentary·14 September 2026·Breaking

Revolut breach: nobody hacked in, and that is the point

Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor argues the real question is not how it happened, but why the process allowed it.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
A smartphone banking app glowing on a dark boardroom table beside a document bearing an official seal, representing the Revolut breach caused by a fraudulent government request
A smartphone banking app glowing on a dark boardroom table beside a document bearing an official seal, representing the Revolut breach caused by a fraudulent government request

Why it matters

What this means for organisations holding critical data

Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor argues the real question is not how it happened, but why the process allowed it.

What happened

Revolut has confirmed that sensitive customer data was disclosed to an unauthorised third party after fraudulent requests for information were submitted from an email account created within a legitimate government agency domain. The request looked genuine, because part of it was.

According to the customer notification reviewed by TechCrunch, the compromised information included dates of birth, postal and email addresses and phone numbers, as well as copies of identity documents such as passports and driving licences. Verification selfies, account statements and transaction histories may also have been exposed.

Revolut says a very limited number of customers were affected and have been contacted directly. It has not disclosed how many people are involved or named the government agency. The company blocked the email address used in the fraud after detecting the incident, alerted the agency, law enforcement, data protection authorities and financial regulators, and says its systems and customer funds were unaffected.

The incident was highlighted publicly by crypto security researcher ZachXBT, who suggested the breach appeared to have targeted high-net-worth users. Revolut has not confirmed that assessment.

We are asking the wrong question

Everyone wants to know how it happened. I am far more interested in why the process allowed it to happen.

Nobody hacked their way in. Nobody bypassed some cutting-edge security control. A request arrived, it looked legitimate enough, and sensitive customer information was handed over. According to reports, the request came from an unauthorised account created within a legitimate government domain, which made it appear genuine enough to be trusted.

That should make every organisation stop and think.

We spend huge amounts of time and money testing technology. We run penetration tests. We monitor alerts. We patch vulnerabilities. We invest in new tools. But how many organisations test the decisions their people make when a request appears to come from an authority they trust?

This is where many businesses get caught out.

Compliant and vulnerable at the same time

Two things can be true at once. You can be compliant, and you can still be vulnerable.

The problem is that many organisations behave as though those two things cannot possibly coexist. I have seen businesses with immaculate policies, successful audits and folders full of evidence. Yet when you start looking at their processes through an attacker's eyes, cracks begin to appear.

Not because they are careless. Not because they are incompetent. Because nobody has ever challenged the process in the real world.

That is the difference between documenting a process and proving it works. The organisations that worry me are not the ones that know they have gaps. It is the ones that are convinced they do not.

The question worth asking

If someone targeted your organisation tomorrow with a legitimate-looking request for customer, employee or financial data, are you confident your process would stop them? Or are you confident your process is documented?

They are not the same thing.

This is also where the data itself matters. Revolut disclosed copies of passports, driving licences and possibly statements and transaction histories because that material was retained and reachable through a routine request process. Where identity records and historical documents must be kept, Offline Secure Storage® keeps them physically disconnected from the systems and inboxes that field incoming requests, so disclosure becomes a deliberate, verified act rather than a response to a convincing email.

Test the process, not just the perimeter. And do not leave your most sensitive records permanently reachable by whoever asks nicely enough.

Mark Fermor is the founder of Firevault.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

CustodyNamed, access-controlled hardware in a Firevault Bunker
EvidenceAccess windows and retrieval events are recorded
SeparationPhysical isolation that satisfies offline copy requirements
JurisdictionStored where your regulatory position requires