Skip to content
Sunday, September 13, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Tech News

Revolut confirms customer data breach through fake government requests

Fraudulent information requests sent from a legitimate government email domain led Revolut to hand over identity documents and verification data to an unauthorized third party.

Asha Venkataswamy · September 13, 2026 · 5 min read
ShareXFacebookLinkedInTelegramEmail
Revolut confirms customer data breach through fake government requests
Revolut confirms customer data breach through fake government requests

Revolut has confirmed that it disclosed sensitive customer information to an unauthorized third party after the party submitted fraudulent requests using a legitimate government agency email domain. The exposed data includes birth dates, postal and email addresses, phone numbers, and copies of passports and driver's licenses. It may also include verification selfies, account statements, and transaction histories, according to the company's notification to affected customers.

The company says it blocked the address after discovering the scam and alerted the relevant government agency, law enforcement, and regulators. It states that Revolut systems and customer funds are unaffected. A spokesperson described the as a "limited" number of impacted customers but did not disclose how many, whether it was confined to one market, or which government agency was involved. For related coverage, see Match Group confirms cybersecurity incident after ShinyHunters claim 10 million records.

The significance of this incident is not the volume of data taken. It is the method. The attacker did not breach Revolut's systems. They convinced a large financial institution, through a channel it trusted, to hand over customer records voluntarily. That distinction matters for every firm that responds to government information requests.

What actually happened?

According to TechCrunch, Revolut confirmed that a "sophisticated external impersonation scam" used a legitimate government agency email to submit fraudulent requests for information. The requests came from a real government email domain, not a spoofed lookalike. That detail is the core of the problem: the verification step most firms rely on, checking the sending domain, would have passed.

The company did not explain how the unauthorized party obtained access to send mail from that domain, or whether the agency itself was compromised. That remains unknown. What is confirmed is the direction of the data flow: Revolut sent the records out in response to requests it believed were lawful.

Crypto security researcher ZachXBT posted about Revolut's notification email late on Friday and said the incident appeared to target high net worth users. That characterization is the researcher's assessment, not something Revolut has confirmed.

Why this method is hard to defend against

Firms receive lawful information requests from governments regularly. Compliance is a legal obligation. The defense challenge is that the usual signals of fraud — an odd domain, an unusual sender, an unprofessional message — are absent when the email genuinely originates from the agency's own infrastructure. Verification must therefore move to a second, out-of-band channel: calling the agency back on an independently confirmed number before releasing documents.

Whether Revolut had such a callback procedure, and whether it was followed, is not known from the available record. The company has not said. This is the question regulators and the affected agency will likely want answered, and it is the question other financial firms should ask of their own compliance teams now.

What the exposed data means for customers

The categories involved are among the most damaging when they leak. Passport and driver's license copies enable identity fraud that is difficult to reverse. Verification selfies, if taken, compound that risk. Transaction histories and account statements reveal financial patterns useful for targeted phishing and social engineering. Readers concerned about this class of exposure can review our privacy coverage on minimizing document sharing, and our threats section tracks incidents of this type.

Revolut says it contacted affected customers directly. Those customers should treat any follow-up communication claiming to be from Revolut or a government agency with caution, since the leaked contact details are precisely what a follow-on scam would use.

The timing question

The incident lands at a sensitive moment for the company. Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries. It recently secured banking licenses in France and the UK, and earlier this month the U.S. Office of the Comptroller of the Currency granted conditional approval for a national bank, which the firm expects to launch in the first half of 2027. TechCrunch also reports the company is weighing a potential public listing that could value it at as much as $200 billion, up from a $75 billion private valuation in November.

A disclosure failure of this kind does not, on the available record, affect funds or core systems. But it touches the two things a bank-in-waiting is judged on: trust in its handling of customer data and the quality of its controls. How quickly and completely Revolut explains the control gap will matter more than the incident itself. For context on disclosure timelines, see how the SEC's four-business-day cyber incident rule works for listed firms, a regime Revolut would enter if it lists. This connects to our earlier piece, How the SEC's four-business-day cyber incident rule actually works.

What is still unknown

Several material questions remain unanswered. The exact number of affected customers is undisclosed. The government agency involved has not been named. It is not known whether the incident was limited to a specific market. And the mechanism by which the unauthorized party sent email from the agency's legitimate domain has not been explained. Until those facts are established, any assessment of scope is provisional. We will update this analysis as the record develops. Readers can follow ongoing coverage in our tech news section.

Sources

  1. Revolut confirms customer data breach through fake government requests - TechCrunchTechCrunch