Security News

Revolut Breach Shows How Fake Government Requests Can Trick Even Fintechs

Infosecurity Magazine · 14 Sept 2026
Key Takeaway Businesses should independently verify any request for sensitive customer data, even ones that appear to come from legitimate government or official domains, before responding.

Revolut has confirmed that a data breach affected a limited group of its customers after fraudsters used a spoofed government agency email domain to request information. The company described it as a 'sophisticated external impersonation scam' in which the fraudulent requests passed valid technical domain authentication checks, leading employees to fulfil them as part of standard legal compliance processes.

According to reports from a crypto-security researcher who shared a customer notification, the exposed data may include full names, dates of birth, addresses, phone numbers, occupations, government ID documents, verification selfies, IBANs, transaction histories and Bitcoin wallet reference numbers. Revolut says customer funds and core systems were not affected, and that it blocked the fraudulent email address, notified affected customers, and alerted regulators and law enforcement once the scam was detected.

Security experts have questioned why a regulated fintech, built around identity verification, did not have stronger controls in place to catch a spoofed government request. Even without financial loss, exposed personal and identity data can be used for identity fraud and highly targeted phishing attacks against affected customers.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.