Revolut confirms it handed customer data to fraudsters posing as a government agency
EditorialBy TrustList Editorial
Revolut confirmed on 12 September 2026 it disclosed identity documents and contact details to an attacker using a real government agency’s email domain; a limited, undisclosed number of customers were affected, and systems and funds were not.
About Revolut confirms it handed customer data to fraudsters posing as a government agency
Revolut confirms it handed customer data to fraudsters posing as a government agency
12 September 2026 — Revolut, the UK fintech, confirmed on 12 September 2026 that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from what its own statement calls "a legitimate government agency domain email." The company describes it as a sophisticated impersonation scam: the attacker used the trust attached to a real government email domain to submit bogus requests for customer information, and Revolut's own processes for verifying such requests did not catch it before data was sent.
What Revolut says was exposed
- Customers' identity and contact details: birth dates, postal and email addresses, and phone numbers.
- Copies of identity documents, including passports and driver's licences, and Revolut says the exposure may also have included verification selfies, account statements and transaction histories.
- Revolut says a "limited" number of customers were affected but has not disclosed the exact number, which markets were involved, or which government agency's domain was impersonated.
What Revolut says it has done
- Blocked the email address used in the scam once it was discovered.
- Notified the impersonated government agency, law enforcement and relevant regulators.
- States that Revolut's own systems and customer funds were not affected — this was a disclosure of data in response to a fraudulent request, not a system intrusion.
Why it matters beyond Revolut
- If your business handles requests for customer data from government agencies or law enforcement, this is a live example of how convincing a spoofed official request can look, and worth using to review your own verification process before sharing data on request.
- Revolut's own account does not say how the fraudulent domain was obtained or spoofed, so the specific technique has not been confirmed publicly as of 25 September 2026.
- If you or your organisation are Revolut customers and have not been contacted directly, Revolut's own statement does not commit to notifying every customer individually, only those it has identified as affected.
Sources
- TechCrunch: Revolut confirms customer data breach through fake government requests — 12 September 2026
- The Register: Revolut falls for fake government requests, hands over customer data — 14 September 2026
- Malwarebytes: Revolut gave customer IDs and financial data to a government impostor — 15 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.