Revolut confirms data breach via fake government requests
Original: Revolut confirms customer data breach through fake government requests
Why This Matters
A breach tied to social engineering at a major fintech underscores systemic risks in emergency data request workflows.
British fintech Revolut confirmed it handed sensitive customer data to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. Exposed data included passports, driver's licenses, selfies, account statements, and transaction histories. The exact number of affected customers was not disclosed.
Revolut confirmed on September 12, 2026, that it disclosed customer data to an unauthorized party after being deceived by fraudulent information requests that spoofed a legitimate government agency email domain. The exposed data included birth dates, postal and email addresses, phone numbers, copies of passports and driver's licenses, and potentially verification selfies, account statements, and transaction histories.
A Revolut spokesperson called it a 'sophisticated external impersonation scam' and said a 'limited' number of customers were affected — though the company declined to reveal the exact count, which market was targeted, or which government agency's domain was exploited. Revolut said it blocked the fraudulent email address, notified law enforcement, and alerted the relevant agency and regulators. Customer funds and Revolut's core systems were described as unaffected.
Crypto security researcher ZachXBT flagged the breach on Friday, suggesting the attack appeared to target high-net-worth users. The timing is notable: Revolut, which serves over 80 million customers across 30+ countries, recently received conditional U.S. banking approval from the OCC, with a national bank launch expected in the first half of 2027. The company is also reportedly eyeing a public listing that could value it at up to $200 billion.