Revolut confirms customer data breach through fake government requests

Hacker News Top News

Summary

Revolut confirmed a customer data breach where sensitive information was disclosed due to fraudulent government impersonation scams, affecting a limited number of users.

No content available
Original Article
View Cached Full Text

Cached at: 09/13/26, 11:37 AM

# Revolut confirms customer data breach through fake government requests | TechCrunch Source: [https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/](https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/) British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain\. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch\. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification\. A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly\. Revolut, however, did not disclose the exact number of impacted individuals\. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved\. “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said\. Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the relevant government agency, law enforcement, and relevant regulators, adding, “Revolut systems and customer funds are unaffected\.” London\-based Revolut has[more than 80 million customers](https://www.revolut.com/about/)globally and operates as a bank in more than 30 countries, per its website\. The fintech recently[expanded its presence](https://techcrunch.com/2026/06/01/revolut-rolls-out-services-to-thousands-of-users-in-india-ahead-of-broader-launch/)in markets including India, Mexico, France, and the UAE\. Moreover, earlier this month, the U\.S\. Office of the Comptroller of the Currency[granted](https://www.reuters.com/business/finance/revolut-wins-conditional-us-banking-license-2026-09-03/)a conditional approval to Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027\. Well\-known crypto security researcher ZachXBT[posted about Revolut’s email](https://t.me/investigations/363)to its affected customers late on Friday\. The researcher said the incident appeared to have been targeted at high net worth users\. The incident comes as Revolut reportedly weighs a potential public listing that could value it at[as much as $200 billion](https://techcrunch.com/2026/04/21/revolut-eyes-valuation-of-up-to-200b-in-eventual-ipo/), up from its[$75 billion private valuation](https://techcrunch.com/2025/11/24/revolut-hits-75b-valuation-in-new-capital-raise/)in November\. The fintech has also been expanding its banking footprint in Europe and globally, securing banking licenses in France and the UK in recent months\. *When you purchase through links in our articles,[we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/)\. This doesn’t affect our editorial independence\.* Jagmeet covers startups, tech policy\-related updates, and all other major tech\-centric developments from India for TechCrunch\. He previously worked as a principal correspondent at NDTV\. You can contact or verify outreach from Jagmeet by emailing[mail@journalistjagmeet\.com](mailto:[email protected])\. [View Bio](https://techcrunch.com/author/jagmeet-singh/)

Similar Articles

LastPass notifies users of yet another data breach

Hacker News Top

LastPass is notifying users of a data breach caused by a compromise at its third-party vendor Klue, exposing customer names, email addresses, and support case data, but not password vaults.

One million passports leaked online

Hacker News Top

Nearly a million passports and photo IDs from multiple European countries were exposed on public URLs with no authentication, accessible to anyone for months. The breach, discovered by security researcher Sammy Azdoufal, occurred due to poor security practices by companies managing age verification for cannabis clubs.

Vercel April 2026 security incident

Hacker News Top

Vercel confirmed a security breach affecting a limited subset of customers after threat actors claimed to have stolen data. The breach originated from a compromised employee Google Workspace account via a third-party AI tool (Context.ai), allowing attackers to access unencrypted environment variables and enumerate further access to customer systems.