---
title: "Revolut breach: nobody hacked in, and that is t… | Firevault"
description: "Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026#webpage",
      "url": "https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026",
      "name": "Revolut breach: nobody hacked in, and that is t…",
      "description": "Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/a9197e4b-c5df-413c-a196-8993df633c93/revolut-fake-government-requests-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Revolut breach: nobody hacked in, and that is the point",
          "item": "https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Revolut breach: nobody hacked in, and that is the point",
      "description": "Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor argues the real question is not how it happened, but why the process allowed it.",
      "url": "https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/a9197e4b-c5df-413c-a196-8993df633c93/revolut-fake-government-requests-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/a9197e4b-c5df-413c-a196-8993df633c93/revolut-fake-government-requests-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/a9197e4b-c5df-413c-a196-8993df633c93/revolut-fake-government-requests-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/a9197e4b-c5df-413c-a196-8993df633c93/revolut-fake-government-requests-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-14T19:00:00+00:00",
      "dateModified": "2026-09-14T19:24:52.563891+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Commentary",
      "wordCount": 609,
      "keywords": "Revolut, Commentary, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened Revolut has confirmed that sensitive customer data was disclosed to an unauthorised third party after fraudulent requests for information were submitted from an email account created within a legitimate government agency domain. The request looked genuine, because part of it was. According to the customer notification reviewed by TechCrunch, the compromised information included da",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened in the Revolut data breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Fraudulent requests for customer information were submitted from an unauthorised email account created within a legitimate government agency domain. Because the request appeared genuine, sensitive customer data was disclosed. No systems were hacked."
          }
        },
        {
          "@type": "Question",
          "name": "What customer data was exposed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Dates of birth, postal and email addresses and phone numbers, plus copies of identity documents such as passports and driving licences. Verification selfies, account statements and transaction histories may also have been exposed."
          }
        },
        {
          "@type": "Question",
          "name": "How many Revolut customers were affected?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Revolut says a very limited number of customers were affected and have been contacted directly, but it has not disclosed a figure. Researcher ZachXBT suggested high-net-worth users appeared to be the target, which Revolut has not confirmed."
          }
        },
        {
          "@type": "Question",
          "name": "Were Revolut's systems or customer funds compromised?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Revolut says its systems and customer funds were unaffected. The breach happened at the process layer: a trusted-looking request was acted on, rather than any technical control being defeated."
          }
        },
        {
          "@type": "Question",
          "name": "Why does Mark Fermor say the industry is asking the wrong question?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Because the focus is on how the breach happened technically, when nothing technical failed. The important question is why the process allowed a fraudulent but legitimate-looking request to succeed, and whether anyone ever tests that decision in the real world."
          }
        },
        {
          "@type": "Question",
          "name": "Would Offline Secure Storage have prevented this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It would have limited what there was to hand over. Identity documents, statements and historical records that must be retained can be kept physically disconnected from the systems that field incoming requests, so disclosure requires deliberate, verified retrieval rather than a reply to a convincing email."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Breaking News Updated as information becomes available 

Overview

What happenedWe are asking the wrong questionCompliant and vulnerable at the …The question worth askingSourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [Opinion](/learn/knowledge?filter=opinion)

Opinion · Commentary · 14 September 2026 · Breaking 

# Revolut breach: nobody hacked in, and that is the point

Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor argues the real question is not how it happened, but why the process allowed it.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Frevolut-fake-government-requests-data-breach-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Frevolut-fake-government-requests-data-breach-2026&text=Revolut%20breach%3A%20nobody%20hacked%20in%2C%20and%20that%20is%20the%20point%0A%0ARevolut%20handed%20sensitive%20customer%20data%20to%20an%20unauthorised%20third%20party%20after%20fraudulent%20requests%20arrived%20from%20a%20legitimate%20government%20domain.%20Mark%20Fermor%20argues%20the%20real%20question%20is%20not%20how%20it%20happened%2C%20but%20why%20the%20process%20allowed%20it.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Frevolut-fake-government-requests-data-breach-2026)[](mailto:?subject=Revolut%20breach%3A%20nobody%20hacked%20in%2C%20and%20that%20is%20the%20point&body=Revolut%20handed%20sensitive%20customer%20data%20to%20an%20unauthorised%20third%20party%20after%20fraudulent%20requests%20arrived%20from%20a%20legitimate%20government%20domain.%20Mark%20Fermor%20argues%20the%20real%20question%20is%20not%20how%20it%20happened%2C%20but%20why%20the%20process%20allowed%20it.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Frevolut-fake-government-requests-data-breach-2026)

![A smartphone banking app glowing on a dark boardroom table beside a document bearing an official seal, representing the Revolut breach caused by a fraudulent government request](/__l5e/assets-v1/a9197e4b-c5df-413c-a196-8993df633c93/revolut-fake-government-requests-2026.jpg)

A smartphone banking app glowing on a dark boardroom table beside a document bearing an official seal, representing the Revolut breach caused by a fraudulent government request

Why it matters

## What this means for organisations holding critical data

Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor argues the real question is not how it happened, but why the process allowed it.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [We are asking the wrong question](#section-1)
3.  03 [Compliant and vulnerable at the …](#section-2)
4.  04 [The question worth asking](#section-3)

**On this page**[What happened](#section-0)[We are asking the wrong question](#section-1)[Compliant and vulnerable at the …](#section-2)[The question worth asking](#section-3)

## What happened

Revolut has confirmed that sensitive customer data was disclosed to an unauthorised third party after fraudulent requests for information were submitted from an email account created within a legitimate government agency domain. The request looked genuine, because part of it was.

According to the customer notification reviewed by TechCrunch, the compromised information included dates of birth, postal and email addresses and phone numbers, as well as copies of [identity documents](/oss-for-identity-documents) such as passports and driving licences. Verification selfies, account statements and transaction histories may also have been exposed.

Revolut says a very limited number of customers were affected and have been contacted directly. It has not disclosed how many people are involved or named the government agency. The company blocked the email address used in the fraud after detecting the incident, alerted the agency, law enforcement, data protection authorities and financial regulators, and says its systems and customer funds were unaffected.

The incident was highlighted publicly by crypto security researcher ZachXBT, who suggested the breach appeared to have targeted high-net-worth users. Revolut has not confirmed that assessment.

## We are asking the wrong question

Everyone wants to know how it happened. I am far more interested in why the process allowed it to happen.

Nobody hacked their way in. Nobody bypassed some cutting-edge security control. A request arrived, it looked legitimate enough, and sensitive customer information was handed over. According to reports, the request came from an unauthorised account created within a legitimate government domain, which made it appear genuine enough to be trusted.

That should make every organisation stop and think.

We spend huge amounts of time and money testing technology. We run penetration tests. We monitor alerts. We patch vulnerabilities. We invest in new tools. But how many organisations test the decisions their people make when a request appears to come from an authority they trust?

This is where many businesses get caught out.

## Compliant and vulnerable at the same time

Two things can be true at once. You can be compliant, and you can still be vulnerable.

The problem is that many organisations behave as though those two things cannot possibly coexist. I have seen businesses with immaculate policies, successful audits and folders full of evidence. Yet when you start looking at their processes through an attacker's eyes, cracks begin to appear.

Not because they are careless. Not because they are incompetent. Because nobody has ever challenged the process in the real world.

That is the difference between documenting a process and proving it works. The organisations that worry me are not the ones that know they have gaps. It is the ones that are convinced they do not.

## The question worth asking

If someone targeted your organisation tomorrow with a legitimate-looking request for customer, employee or financial data, are you confident your process would stop them? Or are you confident your process is documented?

They are not the same thing.

This is also where the data itself matters. Revolut disclosed copies of passports, driving licences and possibly statements and transaction histories because that material was retained and reachable through a routine request process. Where identity records and historical documents must be kept, [Offline Secure Storage](/offline-secure-storage)® keeps them physically disconnected from the systems and inboxes that field incoming requests, so disclosure becomes a deliberate, verified act rather than a response to a convincing email.

Test the process, not just the perimeter. And do not leave your most sensitive records permanently reachable by whoever asks nicely enough.

_Mark Fermor is the founder of Firevault._

## Sources

-   [FStech: Revolut confirms customer data breach after fake government requests](https://www.fstech.co.uk/fst/Revolut_Confirms_Customer_Data_Breach_After_Fake_Government_Requests.php)
-   [Mark Fermor on LinkedIn](https://lnkd.in/eks_CKbi)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![When data theft becomes personal: what we discussed at The Chelmsford Club](/images/news/chelmsford-club-inner-circle-data-theft-briefing-2026.jpg)

Commentary 

### When data theft becomes personal: what we discussed at The Chelmsford Club

Mark Fermor joined the Inner Circle breakfast at The Chelmsford Club to talk about cyber attacks, data theft and what happens when information a business has been trusted to hold ends up in somebody else's hands. The real value of stolen data is not what somebody will pay for it. It is what that information allows them to do next, and the consequence lands personally, professionally and commercially.

9 Sept 2026 20 min 







](/news/data-theft-becomes-personal-chelmsford-club-inner-circle-2026)[

![Nissan / PeopleSoft Breach: When HR Is Also Your Financial Data Repository](/__l5e/assets-v1/5ad05cd5-6f93-4a37-9082-2667ee1b8922/news-nissan-peoplesoft-hero-2x.jpg)

Commentary 

### Nissan / PeopleSoft Breach: When HR Is Also Your Financial Data Repository

Nissan Americas has confirmed employee SSNs, banking and tax data were exposed through the Oracle PeopleSoft zero-day (CVE-2026-35273) campaign linked to ShinyHunters. Mark Fermor on why HR systems keep becoming citizen-scale breaches.

4 Jul 2026 4 min 







](/news/nissan-oracle-peoplesoft-shinyhunters-commentary)[

![Tata / Apple Leak Shows Why Supply-Chain Data Belongs Off the Wire](/__l5e/assets-v1/e4f68a07-04a9-4ba2-bd35-20a50f882eb8/news-tata-apple-supply-chain-hero-2x.jpg)

Commentary 

### Tata / Apple Leak Shows Why Supply-Chain Data Belongs Off the Wire

World Leaks has posted iPhone 18 Pro supplier maps and drop-test photos taken from Apple's Indian manufacturer Tata Electronics. Mark Fermor on why the answer is architectural, not contractual.

4 Jul 2026 4 min 







](/news/tata-apple-iphone-18-supply-chain-leak-commentary)[

![Conwy Council Breaches Show the Insider Threat Regulators Keep Underestimating](/__l5e/assets-v1/d5764ac8-fe12-4751-9512-da1999b5a2c8/news-conwy-council-insider-breach-hero-2x.jpg)

Commentary 

### Conwy Council Breaches Show the Insider Threat Regulators Keep Underestimating

Three separate disciplinary outcomes in one department in twelve months. Mark Fermor on why the Conwy County Council data breaches are a structural warning to every UK local authority, not a one-off.

4 Jul 2026 4 min 







](/news/conwy-council-insider-data-breach-commentary)[

![FortiBleed Proves the IP-Connected Perimeter is Indefensible](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Ffortibleed-inc-lynx-ransomware.jpg)

Commentary 

### FortiBleed Proves the IP-Connected Perimeter is Indefensible

SOCRadar has now tied the FortiBleed credential-harvesting operation directly to INC and Lynx ransomware deployments. Mark Fermor on why physical severance is the only durable answer.

3 Jul 2026 4 min 







](/news/fortibleed-inc-lynx-ransomware-commentary)[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)