Skip to content
Revolut confirms it handed customer data to scammers posing as government agency

Revolut confirms it handed customer data to scammers posing as government agency

Cybernews September 12, 2026

The data reportedly includes copies of identity ⁠documents, such as passports and driver’s licenses, as well as complete transaction histories.

Image via Shutterstock

Scammers obtained Revolut customer data using an email address on a legitimate government agency domain.

Exposed data included details, birth dates, occupations, and identity documents.

Reports say verification selfies, account statements, transaction histories, IBANs, and Bitcoin transactions may also be affected.

Revolut says it blocked the address, alerted authorities, and says customer funds remain unaffected.

Key Takeaways by nexos.ai , reviewed by Cybernews staff.

It’s not just ordinary people who fall for scams – major companies can be fooled, too. British fintech Revolut confirmed it disclosed sensitive customer information after receiving fraudulent data requests from what appeared to be a legitimate government agency email account.

"Upon detection, ⁠we immediately blocked the address and ​alerted the relevant government agency as ​well as enforcement agencies, data protection, and financial regulators," a spokesperson told Reuters on Saturday.

The compromised data included customers' birth dates, postal and email addresses, occupation, and phone numbers, as well as ​copies of ​their identity ⁠documents, including passports and driver’s licenses, according to reports.

TechCrunch reported that verification selfies, account statements, and transaction histories may also have been included. According to a separate report , the compromised data included IBANs, withdrawal records, and complete transaction histories, as well as Bitcoin transactions.

One affected person shared the email received from Revolut on X, complaining that the breach came right after Revolut sent him a notification “to provide a LOT of data or ‘we will close your account in 20 days’”.

The exact number of those affected is undisclosed, but a spokesperson told TechCrunch that the breach impacted a “limited” number of customers, who had been contacted directly.

"Revolut systems and customer ​funds are unaffected," the spokesperson added.

The attack was described as “a sophisticated external impersonation scam” involving an email address on a legitimate government agency domain used to submit fraudulent requests for information. The name of the agency was not released.

Founded in 2015, Revolut serves more than 80 million retail customers and around 800,000 business clients and was valued at $115 billion in a secondary sale launched in July.

In July, an attacker claimed to be selling 75 million Revolut customer records , including card details, emails, names, phone numbers, addresses, device details, and hashed credentials. Revolut said at the time that it found no evidence of a breach, and Cybernews researchers believe the information was aggregated from multiple sources.

Extracted Entities

Attack Types (1)

Companies (1)

Domains (1)

Industries (1)