DMARC-verified-sent from a legitimate [...] domain? -> Someone pwned a mailbox at an agency? I'm sure they would've spun the story into "the government was hacked, not us" in that case.
Or "sent from" a legitimate [...] domain? -> Spoofed envelope sender / FROM? Then Revolut's simply been had by the nose. If the domain is indeed a government domain, and does not publish DMARC records, then a due diligence check on who they're sending such personal info (ie, call that purported government agency up on the phone) would suit them.
After all, they're very pedantic about me running their app on a phone with an unlocked bootloader. I'd then hope that they'd be symmetrically pedantic about verifying whoever they're sending my info to.
An estimated 3% to 5% of the world's entire GDP is linked to criminal activities. The reasons are complex (for example drugs --not my call-- are mostly illegal and drug consumers have a responsibility in enriching cartels) but all the banks of the world "enable money laundering".
I've got many friends who have a Revolut account / card and although I don't have one, it just looks like a nice app / interesting cards (for all the perks and cashback IIUC) to have.
Without specific arguments on what Revolut consistently does that no other bank (e.g. HSBC, wells-fargo etc.) do, you're just yelling at money shaped clouds.