Revolut Data Breach Exposes Customer Records After Fake Government Requests

Revolut has confirmed that sensitive customer information was disclosed to an unauthorised third party after fraudulent data requests were sent from an email account operating within a legitimate government agency domain. The British fintech said the sophisticated impersonation attack affected a limited number of customers, while its systems and customer funds remained secure, raising fresh concerns about how financial firms verify official requests for private data.

The company said the attacker submitted requests that appeared to come from a genuine public authority. Revolut acknowledged that it failed to identify the fraudulent nature of the requests before releasing information. It later blocked the email address and alerted the agency concerned.
Customer notifications reviewed by media outlets indicated that the exposed records could include names, dates of birth, home and email addresses, telephone numbers, identity documents, verification selfies, account statements, IBANs, withdrawal records and transaction histories. Some cryptocurrency transaction information may also have been included.
Revolut has not disclosed the number of affected customers, the markets in which they are located or the government agency whose email account was used. It said the incident was limited in scope and that affected customers were contacted directly.
The fintech stressed that its own systems were not compromised and customer funds were unaffected. The incident appears to have exploited the process used to assess official information requests rather than breaking into Revolut's banking platform.
Revolut said it notified the relevant agency, law enforcement bodies, data protection authorities and financial regulators. The company also introduced additional safeguards and precautionary measures for customers whose information may have been exposed.
The case highlights a weakness that can persist even when an email comes from an authentic domain: the message itself may still be fraudulent. Financial companies handling sensitive legal or regulatory requests may need independent verification channels before releasing customer records.
Customers who receive a breach notice should follow Revolut's guidance, review account activity and remain alert to targeted phishing attempts that use personal details to appear convincing.
Source: Reuters, 12 September 2026


