Skip to content
TrustList
News

Revolut confirms it handed customer data to fraudsters posing as a government agency

Editorial

By TrustList Editorial

Revolut confirmed on 12 September 2026 it disclosed identity documents and contact details to an attacker using a real government agency’s email domain; a limited, undisclosed number of customers were affected, and systems and funds were not.

About Revolut confirms it handed customer data to fraudsters posing as a government agency

Revolut confirms it handed customer data to fraudsters posing as a government agency

12 September 2026 — Revolut, the UK fintech, confirmed on 12 September 2026 that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from what its own statement calls "a legitimate government agency domain email." The company describes it as a sophisticated impersonation scam: the attacker used the trust attached to a real government email domain to submit bogus requests for customer information, and Revolut's own processes for verifying such requests did not catch it before data was sent.

What Revolut says was exposed

  • Customers' identity and contact details: birth dates, postal and email addresses, and phone numbers.
  • Copies of identity documents, including passports and driver's licences, and Revolut says the exposure may also have included verification selfies, account statements and transaction histories.
  • Revolut says a "limited" number of customers were affected but has not disclosed the exact number, which markets were involved, or which government agency's domain was impersonated.

What Revolut says it has done

  • Blocked the email address used in the scam once it was discovered.
  • Notified the impersonated government agency, law enforcement and relevant regulators.
  • States that Revolut's own systems and customer funds were not affected — this was a disclosure of data in response to a fraudulent request, not a system intrusion.

Why it matters beyond Revolut

  • If your business handles requests for customer data from government agencies or law enforcement, this is a live example of how convincing a spoofed official request can look, and worth using to review your own verification process before sharing data on request.
  • Revolut's own account does not say how the fraudulent domain was obtained or spoofed, so the specific technique has not been confirmed publicly as of 25 September 2026.
  • If you or your organisation are Revolut customers and have not been contacted directly, Revolut's own statement does not commit to notifying every customer individually, only those it has identified as affected.

Sources