IT-PUB NEWS

Revolut confirms data breach after fake government requests

14.09.2026 12:03 • Author: IT-PUB

Revolut confirms data breach after fake government requests

Fraudsters used a real government email domain to obtain customer data, including identity details. Revolut says accounts and funds were not affected.

British fintech Revolut has confirmed that it shared sensitive customer information with an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The company says only a limited number of customers were affected, but it has not disclosed how many people were involved or which market was hit. That has made the incident notable: this was not a direct breach of Revolut’s systems, but a case of attackers exploiting trust in official-looking communication. Revolut described it as a “sophisticated external impersonation scam” and said it has notified the relevant government agency, law enforcement, and regulators.

Sensitive documents were exposed

In a notice sent to affected customers and reviewed by TechCrunch, Revolut said the exposed data included identity and contact details such as birth dates, postal and email addresses, and phone numbers.

The notification also said copies of identity documents may have been involved, including passports and driver’s licenses. Verification selfies, account statements, and transaction histories may also have been part of the exposure.

That makes the breach more serious than a routine leak of contact details. Data such as identity documents and account records can be used in scams, identity theft attempts, or other fraud, even if payment systems themselves were not compromised.

Revolut says systems and funds were not affected

A Revolut spokesperson told TechCrunch that the company blocked the email address after discovering the scam and said its systems and customer funds were unaffected. IT-PUB News notes that Revolut has also not identified the government agency whose email domain was used in the fraudulent requests.

The firm did not disclose the exact number of impacted customers. It also declined to say whether the incident was limited to a specific country or market.

Revolut said it had contacted affected customers directly. Its account of the incident suggests the breach happened after the unauthorized third party used the official-looking email domain to submit information requests, rather than by breaking into Revolut’s internal infrastructure.

Official-looking requests created the real risk

The case points to a difficult problem for digital financial services: even when security systems hold up, attackers can still try to exploit trust in messages that appear to come from legitimate institutions. Here, the request seems to have looked credible because it came from a real government agency domain.

For customers, that distinction matters. The central issue was not technical access to Revolut’s platform, but the manipulation of a process that led to data being disclosed. Personal and identity information may now be in outside hands.

Revolut has not said whether affected customers were chosen for any specific reason. Crypto security researcher ZachXBT posted about the email late on Friday and said the incident appeared to have targeted high net worth users, but Revolut did not confirm that.

The disclosure comes as Revolut expands globally

The disclosure comes as Revolut continues to grow quickly. The London-based fintech says it has more than 80 million customers globally and operates as a bank in more than 30 countries.

It has also been expanding into new markets, including India, Mexico, France, and the UAE. Earlier this month, the U.S. Office of the Comptroller of the Currency granted conditional approval for Revolut to set up a national bank in the United States, which the company expects to launch in the first half of 2027.

That timing could bring added scrutiny to the company’s controls and compliance procedures. Revolut is also reportedly considering a public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November. At the same time, it has been building out its banking footprint in Europe and globally, including securing banking licenses in France and the UK in recent months.

For customers, the immediate problem is not interrupted payments or frozen accounts, but personal data that could be misused later. For Revolut, the incident shows how an impersonation scheme can trigger reputational and regulatory pressure even when core banking systems remain untouched.


Improve SEO for a small/medium business website for $50