SOCLYDE logo
Current languageEN
Cybersecurity newsData breachFintechImpersonation

Revolut: customer data disclosed after fake government requests

Revolut confirmed that sensitive customer data was disclosed to an unauthorized third party after fraudulent requests appeared to come from a legitimate government agency domain.

By Soclyde Team

Phone verification of a sensitive customer data request

In summary

  • On September 12, 2026, Revolut confirmed that customer information was disclosed to an unauthorized third party after fraudulent requests used a legitimate government agency email domain.
  • Customer notices reviewed by media outlets listed identity and contact data, document copies and, in some cases, verification selfies, account statements and transaction histories.
  • Revolut says its systems and customer funds were unaffected; the main risk is identity fraud, blackmail, targeted phishing and personal safety for exposed people.

Explore next

Soclyde resources

Article contents

Revolut confirmed on September 12, 2026, that sensitive information about some customers was disclosed to an unauthorized third party. The requests appeared to come from an email address on a legitimate government agency domain, leading the company to treat them as official requests before the impersonation was identified.

This is different from a classic banking-app intrusion. Revolut says its internal systems and customer funds were unaffected. The core issue is procedural: when an official-looking request is accepted without enough independent verification, identity and transaction data can leave through an administrative channel that is normally trusted.

What Revolut confirmed

Revolut's public account describes an external impersonation scam in which an unauthorized third party used a legitimate government agency email domain to submit fraudulent information requests. The company says it blocked the address after detecting the scam and alerted the relevant agency, law enforcement, data protection authorities and financial regulators.

Revolut describes the affected group as limited and says those customers were contacted directly. It has not published an official count, identified the government agency or publicly said whether the incident was limited to one country or one type of customer. That means the public scope should remain narrow: this article describes the data categories mentioned in notices and statements, not an independently verified customer-by-customer inventory.

Data listed in customer notices

TechCrunch says it reviewed a notification sent to affected customers. The notice listed identity and contact details, including date of birth, postal address, email address and phone number, as well as copies of identity documents such as passports or driver's licenses. Other categories could also have been involved in some cases, including verification selfies, account statements and transaction histories.

ITPro also described a highly sensitive scope: identity documents, the facial verification image used at sign-up, IBAN, account status, account opening date, wallet reference number, withdrawal records and full transaction history including Bitcoin. These categories do not prove that every affected customer had every field disclosed. They do show why this is more than an email-address leak: the information can help criminals pass identity checks, prepare financial fraud or pressure a specific person.

Why the government domain matters

A request from an official domain is not automatically a legitimate request. That is the point of the incident: the requests appeared tied to a public authority, while Revolut says they came from an unauthorized third party. The public reporting does not establish whether a government mailbox was compromised, an internal account was abused or another sending mechanism was used.

The operational problem is that many organizations treat official authority requests as a separate flow from the customer relationship. The customer does not see the request, cannot challenge it before disclosure and cannot authenticate its origin. If that channel relies mainly on the appearance of an email domain instead of out-of-band validation, an attacker can deceive the process without breaking into the bank's technical vault.

What notified customers should do

If you receive a Revolut notification, avoid links in unexpected messages and open the app or official website yourself. First, confirm the alert through in-app support or another official channel you already know. Keep the notice, record the data categories listed and watch for contacts that use exact personal details to create urgency.

If identity documents or account statements were disclosed, the risk includes impersonation, account opening elsewhere, support fraud, targeted physical threats and blackmail. Reused passwords should be changed first on email, financial services, crypto platforms and any account capable of resetting other access. No caller or sender should receive a code, document copy, recovery phrase, full IBAN or additional proof without verification through a second channel.

What organizations should review

For a bank, fintech or any company that processes official requests, the control to strengthen is not only the email filter. The process should verify the request through an independent channel, record the requesting authority, confirm the legal basis, minimize the data disclosed and require two-person approval when identity documents or financial histories are involved.

Teams also need logging for every step: request received, identity verified, data extracted, approver, transfer medium and alerts for unusual volume. A government domain, even one that passes technical authentication, should not be enough to release a complete customer file. The Revolut incident shows that administrative procedures can become an attack surface just like an API or an employee account.

The Soclyde connection

Soclyde does not protect Revolut, verify government requests or undo data already disclosed. Its role is narrower: help a small team or independent professional avoid turning an identity-data leak into account compromise through reused secrets. A unique password for every service, stored in a local-first encrypted vault, makes rotation much more realistic when an email address or customer profile becomes a target.

That discipline does not replace verification of official requests or identity-fraud monitoring. It reduces the domino effect: if documents, an address and transaction history make a phishing attempt credible, the attacker should not also find the same password on email, crypto platforms and work tools. To structure that foundation, read the secure password generator guide or contact Soclyde.

Key points

The September 2026 Revolut incident shows that data can leak through a trusted procedure rather than a visible technical intrusion. Revolut confirms a limited group of affected customers, an address blocked after detection, authorities alerted and no announced impact on systems or funds. The data described in customer notices is still sensitive enough to support identity fraud or highly personalized phishing.

The practical response is to verify any notice through a channel you open yourself, refuse pressure to provide new documents or codes, rotate reused passwords and monitor for identity abuse. For organizations, an official request should be authenticated by independent proof, not only by an email domain that appears legitimate.

Frequently asked questions

How many Revolut customers were affected?

Revolut has publicly described the group as limited or very limited and says the affected people were contacted directly. It has not published an official number, market scope or agency name. Later estimates should therefore remain attributed to their sources.

Were Revolut accounts or funds hacked?

Revolut says its systems and customer funds were unaffected. The documented incident concerns customer data disclosed in response to fraudulent requests, not a confirmed public compromise of customer accounts or Revolut's core infrastructure.

What should a notified customer do now?

Verify the notice through the Revolut app or another official channel opened manually, keep the notification, watch for phishing or extortion attempts, rotate any reused passwords and do not send documents, codes or banking information to an unverified contact.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading