https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/

British fintech giant Revolut has confirmed that sensitive customer data was handed over to an unauthorised third party after staff were deceived by fraudulent information requests sent from a legitimate government agency email domain. The exposed data was significant in scope, covering customers’ full identity and contact details including birth dates, postal addresses, email addresses and phone numbers, as well as copies of identity documents such as passports and driver’s licences. Depending on the individual customer, the breach may also have included verification selfies, account statements and transaction histories. Revolut described the incident as a sophisticated external impersonation scam and said it blocked the email address once the fraud was discovered, before alerting the relevant government agency, law enforcement and applicable regulators. The company confirmed that its own systems and customer funds were not compromised.

Revolut declined to disclose how many customers were affected beyond describing the number as limited, and refused to identify the government agency whose email domain was spoofed or confirm whether the incident was contained to a specific market. The company did confirm it had contacted affected customers directly. Crypto security researcher ZachXBT, who first drew public attention to the breach after the customer notification circulated online, suggested the incident appeared to have been deliberately targeted at high-net-worth users rather than representing a broad sweep of the customer base, raising the possibility that the attackers had prior knowledge of which accounts were worth pursuing.

The timing is notable given the broader context surrounding Revolut. The London-based company, which serves more than 80 million customers across more than 30 countries, is reportedly weighing a public listing that could value it at as much as $200 billion, nearly triple its $75 billion private valuation from late last year. It has also been on an active expansion push, recently securing banking licences in France and the United Kingdom and receiving conditional approval from the US Office of the Comptroller of the Currency to establish a national bank stateside, expected to launch in the first half of 2027. The breach highlights a growing threat vector that does not require attackers to break through technical defences at all, instead exploiting the trust organisations place in official communication channels to extract sensitive data through entirely conventional request processes.

Discover more from Edwin Kwan

Subscribe now to keep reading and get access to the full archive.

Continue reading