Techcrunch Revolut Data Breach: Fraudulent Government Email Exposes Customer Information
Article Content
- •Revolut disclosed sensitive customer data due to a fraudulent government email request.
- •The exposed data includes identity documents and complete transaction histories, including Bitcoin.
- •No customer funds were compromised, and the breach primarily affected a limited number of high-net-worth individuals.
On September 11 and 12, 2026, Revolut disclosed sensitive customer data after falling victim to a sophisticated impersonation scam. An unauthorized party sent a fraudulent data request using a legitimate government agency's email domain, which passed all security checks. The exposed information includes full names, dates of birth, addresses, email addresses, phone numbers, identity documents, verification selfies, IBANs, and complete transaction histories, including Bitcoin activity. Revolut has stated that the number of affected customers is limited, primarily targeting high-net-worth individuals. No passwords, PINs, or biometric data were compromised, and customer funds remain unaffected. The company has alerted relevant authorities and blocked the fraudulent email address. Notifications to affected customers began on September 11, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track Revolut in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…