Revolut confirms customer data breach through fake government requests
Recorded: Sept. 13, 2026, 11:09 a.m.
| Original | Summarized |
Revolut confirms customer data breach through fake government requests | TechCrunch Disrupt 2026: OpenAI, Anthropic, Replit, and more take over 6 industry stages. 25% off tickets now Back by popular demand: Save up to $300 on Disrupt Close TechCrunch Desktop Logo TechCrunch Mobile Logo LatestStartupsVentureAppleSecurityAIAppsDisrupt 2026 EventsPodcastsNewsletters SearchSubmit Site Search Toggle Mega Menu Toggle Topics Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Government & Policy Hardware Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture More from TechCrunch Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Contact Us Image Credits:Revolut Security
Revolut confirms customer data breach through fake government requests Jagmeet Singh 7:40 AM PDT · September 12, 2026
British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved. The incident comes as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November. The fintech has also been expanding its banking footprint in Europe and globally, securing banking licenses in France and the UK in recent months. Topics Fintech, Revolut, Security, United Kingdom, United States When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Jagmeet Singh Reporter Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. View Bio October 13 – 15 Last day to book an exhibit table is September 18. Don’t miss out on high-impact leads, investor access, and a brand spotlight in Disrupt’s Expo Hall. BOOK NOW Most Popular Revolut confirms customer data breach through fake government requests Jagmeet Singh OpenAI puts Pro subscriptions on hold due to Astra demand Sarah Perez ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen Zack Whittaker Automattic’s board forces CEO Matt Mullenweg into leave of absence Julie Bort Apple unveils its first foldable, the iPhone Duo Ivan Mehta OpenAI fought dirty on career-making math problem, says NYU mathematician Russell Brandom A secret new Elizabeth Holmes documentary stuns Telluride Connie Loizos Loading the next article Error loading the next article X TechCrunchStaffContact UsAdvertiseSite Map © 2026 TechCrunch Media LLC. |
British fintech company Revolut confirmed that it disclosed sensitive customer information following a data breach that originated from fraudulent requests sent using a legitimate government agency email domain. The exposed data included comprehensive customer information such as identity and contact details, including birth dates, postal and email addresses, and phone numbers, along with copies of identity documents like passports and driver’s licenses. The company further indicated that the compromised data may have also encompassed verification selfies, account statements, and transaction histories. A spokesperson for Revolut informed TechCrunch that a limited number of customers were affected and that the company had directly contacted those individuals. However, Revolut refrained from disclosing the exact number of impacted customers, the specific market affected, or the identity of the government agency involved in the fraudulent requests. The spokesperson assured that Revolut systems and customer funds remained unaffected by the incident. The spokesperson further explained that the security incident involved a sophisticated external impersonation scam where an unauthorized third party exploited a legitimate government email domain to submit fraudulent information requests. Revolut operates globally, serving more than 80 million customers across over 30 countries, with recent expansion into markets including India, Mexico, France, and the United Arab Emirates. This security event occurred while the fintech was also navigating a potential public listing valued up to two hundred billion dollars, up from its previous private valuation of seventy-five billion dollars. Furthermore, the company has been actively expanding its banking footprint in Europe, having secured banking licenses in France and the United Kingdom. Outside of the company's statement, crypto security researcher ZachXBT commented on the incident, suggesting that the breach appeared specifically targeted towards high net worth users. |