№255|04:21 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

Revolut Confirms Customer Data Exposed Through Fraudulent Government Agency Requests

Revolut confirmed it exposed sensitive customer data — including passport copies and transaction histories — after fraudulent requests were submitted using a legitimate government agency's email domain. The fintech said a "limited" number of customers were affected and that company systems and funds remain unaffected.

SM
Sara Montes de Oca
SEP 12, 2026 · 03:01 PM ET · 2 MIN READ
via Wikipedia (Revolut)

British fintech Revolut has confirmed that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency's email domain, as first reported by TechCrunch.

The exposed information included customers' identity and contact details — birth dates, postal and email addresses, and phone numbers — as well as copies of identity documents such as passports and driver's licenses. The compromised data may have also included verification selfies, account statements, and transaction histories, according to a notification Revolut sent directly to affected customers.

A Revolut spokesperson described the incident as "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."

The company said a "limited" number of customers were impacted, though it did not specify an exact figure. Revolut also declined to identify the government agency involved or to confirm whether the exposure was limited to customers in a particular country.

After discovering the scam, Revolut said it blocked the relevant email address and notified the agency in question, law enforcement, and applicable regulators. "Revolut systems and customer funds are unaffected," the spokesperson said.

Well-known crypto security researcher ZachXBT drew public attention to the incident late Friday after posting about the notification email sent to affected customers. ZachXBT said the incident appeared to have been directed at high-net-worth users.

London-based Revolut serves more than 80 million customers globally and operates as a bank in more than 30 countries. The company has been on an aggressive expansion drive, recently entering markets including India, Mexico, France, and the UAE.

Earlier this month, the U.S. Office of the Comptroller of the Currency granted Revolut a conditional approval to establish a national bank in the United States, which the firm expects to launch in the first half of 2027.

The breach comes at a sensitive moment for the fintech. Revolut is reportedly weighing a potential public listing that could value the company at as much as $200 billion — up sharply from its $75 billion private valuation in November. The company has also been building out its European banking footprint, securing banking licenses in both France and the United Kingdom in recent months.

The episode underscores an evolving attack vector in which threat actors exploit the trusted appearance of official government channels to extract data from companies that have legal obligations to respond to such requests. As Revolut pursues a U.S. banking charter and a potential IPO, how it handles the regulatory fallout from the incident is likely to attract close scrutiny from both financial watchdogs and prospective investors.

Disclaimer

SM
━ ABOUT THE REPORTER
Sara Montes de Oca

Sara Montes de Oca is the Editor in Chief of TechEchelon. Previously a correspondent and producer in Washington, D.C., covering business, finance, and politics.

More from Sara
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime