Raw data, clear context.

[
[
[

]
]
]

Revolut has confirmed that an unauthorised party obtained sensitive customer information after sending fraudulent requests from a legitimate government email domain. A 15 September post by Korra reports an alleged mechanism involving compromised government employee accounts and an infostealer. TechCrunch and The Record report the disclosure and response, not that mechanism, which remains a source claim.[2][3][1]

The new account is a reported allegation

Korra’s post is a source account that relays information said to have come from the alleged attacker. It is not an official incident report. According to the post, the alleged attacker accessed government employee accounts with an infostealer, added a recovery address, monitored replies and deleted messages that could have exposed the activity.[1]

The post also says the alleged attacker controlled messages that appeared to come from multiple Italian government addresses.[1] That is a narrower claim than access to government systems, databases or networks. This article does not infer any of those broader forms of access from the reported control of email accounts.

The same post claims that the alleged attacker selected Revolut Bank UAB, described in the post as the Lithuania-based entity, because it would respond to a European Investigation Order. It further claims that requests were sent over roughly five months and that Revolut supplied information after treating them as government requests.[1] These propositions remain attributed claims. The post does not provide a public forensic record that independently establishes the alleged mailbox access, the request period or each data transfer.

A detailed account is not the same thing as an authenticated mailbox log or a verified request record. The source account’s contact with the alleged attacker cannot be independently verified from the public material reviewed here.

What PEC establishes, and what it does not

AgID says that PEC can provide a certain date of sending, message integrity and certification of delivery. A message sent from one PEC mailbox to another has the legal value of a registered letter with acknowledgement of receipt.[4]

The page describes properties of the message and its delivery. It does not establish who operated the account, whether the account had been taken over or whether the person sending a message had authority to make the request. The distinction is important, but it is an analytical boundary drawn from the documented properties of PEC, not a statement by AgID about the Revolut case.

The European Investigation Order is a separate legal instrument. The European e-Justice Portal describes it as a judicial decision issued or validated by an authority in one EU country to gather evidence in another. Its overview refers to mutual recognition and says that an order must be necessary, proportionate and allowed in similar domestic cases.[5]

That general description does not establish that a document shown in a social-media post was a valid European Investigation Order. It also does not describe Revolut’s internal verification process or establish a general legal rule for how the company had to assess a request. Those questions require current, jurisdiction-specific legal and operational records that are not in the public material reviewed here.

Three evidence states should remain separate

The confirmed event is Revolut’s disclosure of sensitive information after fraudulent requests arrived from a legitimate government agency email domain. TechCrunch reported Revolut’s statement that a limited number of customers were affected, that the company contacted them and that its systems and customer funds were unaffected.[2]

Separate reporting describes the possible data categories. The Record reported that customer notices shared by affected individuals listed birth dates, addresses, phone numbers, identity documents, verification selfies, statements, IBANs, withdrawal records and transaction histories.[3] The wording describes what the notices said could be exposed. It does not show that every category was delivered to every affected customer.

The third evidence state is Korra’s account of the alleged mechanism. It adds detail about an infostealer, government employee accounts, recovery addresses, message monitoring and repeated requests, but those details come from an alleged attacker relayed through a source account.[1] The FBI’s earlier warning shows that fraudulent emergency data requests using compromised government email addresses are a documented threat pattern, not that this incident followed that pattern.[6]

These states should not be merged. A compromise of a government mailbox, misuse by an authorised insider, compromise of wider government systems, compromise of Revolut’s systems and a failure in a disclosure process are different hypotheses. Each requires different records.

The records that could resolve the claim

The most useful next evidence would be administrative rather than dramatic: authentication logs for the relevant government mailbox, records showing when recovery details changed, message headers, provider audit trails and a verified list of requests sent to Revolut. Those records could establish whether the account was accessed, when control changed and which requests were actually transmitted.

Later reporting supplies an approximate customer-notification count. RTÉ reported that about 680 customers worldwide had been identified, including 12 in Ireland, while City AM reported that Revolut had contacted 680 people, citing a source close to the bank.[7][8] These are attributed reports about customers contacted or identified, not an audited forensic perimeter. They do not establish the number of fraudulent requests, the number successfully answered or the fields transferred to each person.

City AM also reported that the Financial Conduct Authority was engaging with Revolut to understand the impact and that the Information Commissioner’s Office had received a report and was assessing the information.[8] Those statements indicate regulatory engagement, not a finding that a breach of UK data-protection law occurred.

As of 15 September 2026, the reviewed public material does not identify the agency or domain, verify the mailbox-compromise account or establish the number and content of requests. It does provide an approximate customer-notification count through attributed reporting. These are bounded statements about the sources checked, not proof that no further record exists.

The decisive record would connect one government account, one request and one transfer of data. Until that chain is available or confirmed by the relevant authorities, the mailbox mechanism remains an allegation rather than an established finding.

Sources

[1] Korra (@korraflow), X post, 15 September 2026

[2] TechCrunch, Revolut confirms customer data breach through fake government requests

[3] The Record, Revolut handed customer data to fraudsters using government email account

[4] AgID, Posta elettronica certificata

[5] European e-Justice Portal, European Investigation Order

[6] FBI IC3, Easy Access to Information for Conducting Fraudulent Emergency Data Requests

[7] RTÉ, 12 Irish Revolut customers said to be impacted by breach

[8] City AM, Revolut hackers stole nearly 700 customers’ private data