Skip to content
Social engineeringContained

Revolut confirms customer data breach through fake government data requests

British fintech Revolut disclosed that an unauthorized party used a legitimate government agency's email domain to submit fraudulent requests and obtain sensitive data on a limited number of customers, reportedly targeting high-net-worth users.

Victim
Revolut

On 12 September 2026, Revolut β€” the London-headquartered fintech and banking app used by tens of millions of customers worldwide β€” confirmed that an unauthorized third party had obtained sensitive customer information through fraudulent data requests. According to the company, the attacker used a legitimate government agency's email domain to submit requests for information, exploiting the trust that firms extend to lawful government demands. Revolut did not identify which agency's domain had been abused.

The exposed data was significant in depth even if limited in reach: it included identity and contact details such as dates of birth, postal and email addresses and phone numbers, copies of identity documents including passports and driver's licenses, and potentially verification selfies, account statements and transaction histories. Revolut said only a "limited" number of customers were affected but declined to give a figure; crypto researcher ZachXBT suggested the breach had targeted high-net-worth users, a profile that heightens the fraud and physical-security risk for those involved.

Trust in government channels as the attack surface

The incident stands out because it did not rely on breaching Revolut's technical defences at all. Instead it abused the legitimate process by which authorities request customer data, turning a compromised or spoofed government email domain into a channel for extracting personal information β€” a social-engineering technique that has repeatedly defeated large platforms.

Revolut said it blocked the fraudulent email address, notified affected customers, and alerted law enforcement, relevant regulators and the impersonated government agency, adding that its systems and customer funds were unaffected. Because the abused channel was shut down and the exposure was confined to a limited set of customers, the incident was assessed as contained, though the sensitivity of the stolen identity documents leaves lasting risk for those targeted.

Timeline

  1. Revolut publicly confirms that an unauthorized third party obtained customer data by impersonating a government agency through its email domain, and says it has blocked the fraudulent address and notified affected customers, regulators and the impersonated agency.

Sources

  1. techcrunch.comhttps://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
  2. privacyguides.orghttps://www.privacyguides.org/news/2026/09/18/data-breach-roundup-sep-11-17-2026/

Related incidents

Social engineeringContained

C&M Software Pix heist (Brazil, 2025)

A junior developer at C&M Software β€” a Central Bank-authorized provider of Pix instant-payment connectivity β€” was paid roughly R$5,000 to hand over credentials. Attackers used the access to drain approximately R$800 million ($148 million) from reserve accounts at six Brazilian financial institutions in 2.5 hours.

Victim
C&M Software (Pix payment infrastructure provider)
Loss
$148.0M