LmCast :: Stay tuned in

Revolut confirms customer data breach through fake government requests

Recorded: Sept. 13, 2026, 11:09 a.m.

Original Summarized

Revolut confirms customer data breach through fake government requests | TechCrunch

Disrupt 2026: OpenAI, Anthropic, Replit, and more take over 6 industry stages. 25% off tickets now

Back by popular demand: Save up to $300 on Disrupt

Close

TechCrunch Desktop Logo

TechCrunch Mobile Logo

LatestStartupsVentureAppleSecurityAIAppsDisrupt 2026

EventsPodcastsNewsletters

SearchSubmit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Contact Us

Image Credits:Revolut

Security

Revolut confirms customer data breach through fake government requests

Jagmeet Singh

7:40 AM PDT · September 12, 2026

British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.
The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.

A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.
Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the relevant government agency, law enforcement, and relevant regulators, adding, “Revolut systems and customer funds are unaffected.”
London-based Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries, per its website. The fintech recently expanded its presence in markets including India, Mexico, France, and the UAE. Moreover, earlier this month, the U.S. Office of the Comptroller of the Currency granted a conditional approval to Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027.
Well-known crypto security researcher ZachXBT posted about Revolut’s email to its affected customers late on Friday. The researcher said the incident appeared to have been targeted at high net worth users.

The incident comes as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November. The fintech has also been expanding its banking footprint in Europe and globally, securing banking licenses in France and the UK in recent months.

Topics

Fintech, Revolut, Security, United Kingdom, United States

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Jagmeet Singh

Reporter

Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV.
You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com.

View Bio

October 13 – 15
San Francisco

Last day to book an exhibit table is September 18. Don’t miss out on high-impact leads, investor access, and a brand spotlight in Disrupt’s Expo Hall.

BOOK NOW

Most Popular

Revolut confirms customer data breach through fake government requests

Jagmeet Singh

OpenAI puts Pro subscriptions on hold due to Astra demand

Sarah Perez

ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen

Zack Whittaker

Automattic’s board forces CEO Matt Mullenweg into leave of absence

Julie Bort
Sarah Perez

Apple unveils its first foldable, the iPhone Duo

Ivan Mehta

OpenAI fought dirty on career-making math problem, says NYU mathematician

Russell Brandom

A secret new Elizabeth Holmes documentary stuns Telluride

Connie Loizos

Loading the next article

Error loading the next article

X
LinkedIn
Facebook
Instagram
youTube
Mastodon
Threads
Bluesky

TechCrunchStaffContact UsAdvertiseSite Map
Terms of ServicePrivacy PolicyRSS Terms of UseCode of Conduct
OpenAIHugging FaceFlockStartup BattlefieldDisrupt 2026Tech LayoffsChatGPT

© 2026 TechCrunch Media LLC.

British fintech company Revolut confirmed that it disclosed sensitive customer information following a data breach that originated from fraudulent requests sent using a legitimate government agency email domain. The exposed data included comprehensive customer information such as identity and contact details, including birth dates, postal and email addresses, and phone numbers, along with copies of identity documents like passports and driver’s licenses. The company further indicated that the compromised data may have also encompassed verification selfies, account statements, and transaction histories.

A spokesperson for Revolut informed TechCrunch that a limited number of customers were affected and that the company had directly contacted those individuals. However, Revolut refrained from disclosing the exact number of impacted customers, the specific market affected, or the identity of the government agency involved in the fraudulent requests. The spokesperson assured that Revolut systems and customer funds remained unaffected by the incident. The spokesperson further explained that the security incident involved a sophisticated external impersonation scam where an unauthorized third party exploited a legitimate government email domain to submit fraudulent information requests.

Revolut operates globally, serving more than 80 million customers across over 30 countries, with recent expansion into markets including India, Mexico, France, and the United Arab Emirates. This security event occurred while the fintech was also navigating a potential public listing valued up to two hundred billion dollars, up from its previous private valuation of seventy-five billion dollars. Furthermore, the company has been actively expanding its banking footprint in Europe, having secured banking licenses in France and the United Kingdom. Outside of the company's statement, crypto security researcher ZachXBT commented on the incident, suggesting that the breach appeared specifically targeted towards high net worth users.