Cybersecurity

Revolut Confirms Customer Data Leak Following Fake Government Requests

Revolut confirmed that it exposed sensitive data belonging to a limited number of customers after employees responded to fraudulent requests sent from an email domain belonging to a legitimate government agency. The potentially exposed data includes identity documents, account records, and transaction records, while the company has not disclosed the number of affected customers or the government agency involved.

2026-09-12
3 min read
12 views
فريق تحرير certi.news
Revolut Confirms Customer Data Leak Following Fake Government Requests

British financial services company Revolut confirmed an incident in which sensitive data belonging to a limited number of customers was exposed to an unauthorized party after it received fraudulent information requests sent from an email domain belonging to a legitimate government agency. The company said it directly notified affected customers and also alerted the relevant government agency, law enforcement agencies, and pertinent financial regulators.

According to a notice Revolut sent to customers and which TechCrunch reviewed, the exposed data included identity and contact information, such as dates of birth, postal addresses, email addresses, and phone numbers. The data also included copies of identity documents, including passports and driver's licenses. The company explained that the information may also have included personal verification photos, account statements, and transaction records.

Details Remain Undisclosed

Revolut did not specify the exact number of affected customers, describing it only as a “limited” number. It also did not clarify whether the incident was confined to a particular market and declined to disclose the name of the government agency whose email domain was used in the impersonation operation.

The company said an unauthorized party used the domain of a legitimate government agency to send fake requests for information. After discovering the scheme, Revolut blocked the email address used and notified the relevant official parties. It added that the company's systems and customers' funds were not affected by the incident, a distinction between a customer data leak and a direct compromise of financial systems or accounts.

Why Does This Matter?

The incident is significant because, according to the information available, the attacker did not breach a government domain or Revolut's system, but instead exploited the trust associated with a legitimate email address to obtain unauthorized disclosure. This makes the incident an example of the risks involved in verifying data requests when the sending party appears official, particularly at financial institutions that handle highly sensitive identity documents and transaction records.

Security researcher specializing in cryptocurrency ZachXBT indicated that the incident appeared to target high-net-worth users, but Revolut did not confirm this information in the notice or the reported statements. The company says it has more than 80 million customers worldwide and operates as a bank in more than 30 countries, making the precise geographic scope of the impact an open question.

Context and Limitations

The incident comes as Revolut expands its banking presence in Europe and other markets, including India, Mexico, France, and the United Arab Emirates. The U.S. Office of the Comptroller of the Currency also granted the company conditional approval to establish a national bank, with its launch expected in the first half of 2027. This also coincided with reports that the company was considering a potential public listing that could value it at $200 billion, compared with a private valuation of $75 billion in November.

The published information does not include the number of affected records, how long the fraudulent requests remained active, or the additional measures regulators will impose. The current picture therefore remains limited to confirmation of the leak and the types of data potentially exposed, without sufficient basis to estimate the final scale or determine whether the incident was connected to a particular market or customer group.

News source
TechCrunch FinTech
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news