Wed 16 Sep 2026 / 10:29 ET
Kernel
Security 3 min read

Revolut customer data breach exposed records through false government requests

Revolut says fraudsters used a legitimate government agency email domain to obtain customer data; the UK privacy regulator is investigating.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Revolut customer data breach exposed records through false government requests
img: The Record

The Revolut customer data breach did not involve a disclosed intrusion into the fintech’s systems. Revolut says it released sensitive customer information after an unauthorized party sent fraudulent requests from an email address using a legitimate government agency domain. The company says its systems and customer funds were unaffected.

The distinction matters. Revolut has confirmed that the sender used a real government-domain address, but it has not publicly named the agency, identified a country or market involved, or explained how the sender obtained or used that address. There is no public confirmation that the agency’s systems were compromised.

What customer data did Revolut disclose?

An affected-customer notification reviewed by TechCrunch said the information included dates of birth, postal and email addresses, phone numbers, and copies of passports or driver’s licences. The notice also said verification selfies, account statements and transaction histories may have been included.

That is a serious collection of identity material, though Revolut has not said that every affected person had every category of data disclosed. Reports of additional information, including Bitcoin activity, have appeared in reporting based on customer notices and online material, but the company has not published a complete account of the data set for each customer.

Revolut initially described the number of people affected only as “limited” or “very limited.” The Financial Times later reported that the company had contacted 680 people it believed were affected, citing people familiar with the matter. Revolut did not confirm that figure publicly.

What has Revolut done after the disclosure?

Revolut says it blocked the email address once it detected the scam and notified the customers involved. It also says it alerted the relevant government agency, law-enforcement bodies, data-protection authorities and financial regulators.

The UK Information Commissioner’s Office is investigating after Revolut reported the incident to the watchdog, according to the Financial Times. The regulator’s investigation does not establish how the fraud occurred or whether Revolut breached data-protection rules; those questions remain open.

The technique is familiar even if the details here are not. The FBI warned in 2024 that criminals had used compromised government email accounts to send fraudulent emergency data requests to companies. That alert is background, not an attribution of this incident to a particular group or method of access.

What remains unknown about the Revolut breach?

  • The government agency and jurisdiction whose email domain was used.
  • How the sender gained access to, or otherwise used, the address.
  • How long the fraudulent requests were sent before Revolut detected them.
  • The precise number of affected customers and the full data set disclosed for each person.
  • Whether claims of an extortion demand or targeting of wealthy crypto customers can be substantiated. Revolut has not confirmed either point.

For now, the confirmed account is narrower than the online chatter: Revolut disclosed data in response to fraudulent information requests sent from a genuine government-agency email domain, has notified affected customers and authorities, and says customer funds and its systems were not affected.

This story draws on original reporting from The Record.

More Security/

view all ↗