Breach tracker

Breach report

Revolut confirms it sent customer data to an impostor using a government email domain

ConfirmedDisclosed Updated United KingdomFinanceBy Vivek Kumar
Records UnknownCause Social engineering
Conceptual illustration: A banking phone and abstract ID documents handed toward an unverified email envelope under a magnifying glass. Headline: REVOLUT DATA HANDOFF.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

Revolut says an unauthorised third party used a real government agency email domain to request customer records, including ID documents. It has not said how many people were affected.

What happened

Revolut confirmed on 12 September 2026 that it had disclosed sensitive customer information to an unauthorised third party. According to the company's statement to TechCrunch, the fraudulent requests came from an email domain belonging to a legitimate government agency, the same kind of channel authorities use to ask banks for customer records. Revolut said it blocked the address once the scam was detected and alerted the agency concerned, law enforcement and regulators.

No one broke into Revolut's systems. A request that looked official was answered.

Confirmed vs. claimed

Confirmed by Revolut: the fake requests, the disclosure, and that its systems and customer funds were not affected. The company told The Register it has contacted the affected people directly.

Not disclosed: how many customers were affected (Revolut says only a "limited number"), which countries they are in, which government agency's domain was used, and how the sender obtained access to it. No group has been publicly identified as responsible.

Who is affected

According to TechCrunch, the data included names, dates of birth, postal and email addresses, phone numbers and copies of passports or driving licences, and may have included verification selfies, account statements and transaction histories. The Register also lists IBANs and occupations. Revolut has not said whether customers in any particular market, including India, were among those affected. Only customers Revolut has contacted are known to be in scope.

What to do

  • Check any message about this incident inside the Revolut app, not through links in email or SMS.
  • Expect targeted fraud. A caller who knows your ID details and recent transactions is not proof they are from Revolut, a bank or the police.
  • Never move money to a "safe account" because a caller asks you to.
  • Work through our checklist on what to do after a data breach notice.
  • In India, report cyber fraud on 1930 or at cybercrime.gov.in.

Sources

More breaches in United Kingdom