Revolut, Fed Incidents Expose Cracks in Banking’s Trust System
Banks typically treat authenticated government requests and regulatory data systems as trusted infrastructure, but incidents involving digital lender Revolut and the U.S. Federal Reserve show why that assumption is increasingly risky. A valid email domain can conceal an unauthorized operator, while an outage at a supervisor’s data hub can disrupt oversight without touching a bank’s core systems. The cases broaden operational-resilience planning beyond internal networks to government channels, regulators and independent verification of a requester’s legal authority.
Revolut said on Sept. 12, 2026, that an unauthorized party used a legitimate government-agency email domain to submit fraudulent information requests, exposing data that may have included identity documents, verification selfies, IBANs and transaction histories. The company said only a limited number of customers were affected and that its systems and customer funds were untouched; it disclosed neither a victim count nor a loss amount. Separately, Senator Elizabeth Warren said on Sept. 15 that the Fed’s National Information Center had been down for at least 48 hours from around Aug. 5, and asked whether a 30% staffing cut impaired maintenance.
All Coverage
1 original reportsThe Backstory
The history behind this eventRevolut Data Leak Exposes Security Gaps Beyond Fines
Revolut’s mobile-first model has helped it reach more than 80 million customers and operate as a bank in over 30 countries, concentrating identity, account and transaction data in a fast-growing platform. The risk is not new: a September 2022 social-engineering attack exposed data tied to 50,150 customers worldwide, including 20,687 in the European Economic Area. The repeated failures sharpen concern that regulatory penalties alone cannot correct weaknesses in verification, access controls and security governance.
On Sept. 11-12, 2026, Revolut notified affected customers that it had fulfilled fraudulent information requests sent from an unauthorized mailbox inside an official government domain. The messages carried valid domain-authentication credentials; records disclosed may have included passports, verification selfies, IBANs, withdrawal data and full transaction histories, including Bitcoin activity. Revolut said its systems and customer funds were unaffected, but did not disclose the number of people involved. The Bank of Lithuania’s separate €3.5 million anti-money-laundering fine on April 8, 2025, underscores how sanctions have yet to dispel broader control concerns.
Compromised Government Email Tricks Revolut Into Releasing Customer Data
Revolut, the UK-based digital bank, disclosed customer files after fraudsters sent information requests from an email account using a legitimate government-agency domain. The episode matters because the material combined know-your-customer records — including passports, driver’s licenses, verification selfies and addresses — with IBANs, withdrawal records and complete transaction histories, including Bitcoin activity. Such a package can enable identity theft, highly tailored phishing and physical targeting of wealthy cryptocurrency holders, even without a breach of the bank’s core systems.
Revolut confirmed the incident on Sept. 12, 2026, saying only a “very limited” number of customers were affected and that its systems and customer funds remained secure. Media reports put the total at about 680, describing many as high-net-worth cryptocurrency users. Italian postal police opened an investigation on Sept. 15 into the compromised government email account. Attackers have claimed they want 10,000 bitcoin, worth about $780 million, and threatened daily releases; Revolut has not verified the ransom demand or authenticated all material posted online.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →