Revolut data breach triggered by fake government requests
The fintech giant leaked sensitive customer identity documents after attackers impersonated a government agency using a legitimate email domain.
Revolut has confirmed a significant data breach occurring in September 2026 that exposed sensitive customer information to an unauthorized third party. The incident underscores a critical vulnerability in how financial institutions validate official requests, as attackers successfully bypassed security protocols through a sophisticated impersonation scam.
According to a Revolut spokesperson, the breach was executed by an external party that utilized a legitimate government agency email domain to submit fraudulent requests for information. This deception led Revolut staff to release sensitive data, including customer birth dates, phone numbers, and postal and email addresses. Most critically, the leak included copies of identity documents, specifically passports and driver's licenses. The company further noted that potential additional leaked data may include account statements, transaction histories—specifically Bitcoin histories—and verification selfies.
The Scale of the Vulnerability
Revolut operates as a global fintech powerhouse with more than 80 million customers and banking licenses in over 30 countries. The company is currently in a phase of aggressive global expansion, targeting growth in the UAE, Mexico, and India. Furthermore, the firm is working toward establishing a national bank in the United States by early 2027, following conditional approval from the U.S. Office of the Comptroller of the Currency.
Industry Implications
This breach highlights a systemic risk in the financial sector: the reliance on email domains as a primary marker of authenticity. By leveraging a legitimate government domain, attackers were able to weaponize trust to conduct social engineering against bank employees. For Revolut, the timing is particularly sensitive. The company is eyeing a potential public listing with a valuation that could reach $200 billion. Security lapses of this nature can erode investor confidence and invite heightened regulatory scrutiny as the firm transitions from a disruptive fintech app to a traditional banking model.
Current Status and Next Steps
Revolut stated that its internal systems remained secure and that customer funds were not affected by the incident. The company has since blocked the fraudulent email address and has notified the affected customers, as well as relevant regulators and law enforcement agencies. Observers will now be watching for the results of the regulatory investigations and whether Revolut implements more stringent, multi-factor verification processes for government-led data requests to prevent similar impersonation attacks.