Trending

    Revolut Exposed Customer Data to Scammers via Legitimate Government Email Domain

    Section editor: ·Moderate6 articles covering this·5 news sources·Updated an hour ago·World
    Share:
    Infographic showing the flow of data from Revolut to scammers, highlighting compliance vulnerabilities.

    If you use fintech services, this incident highlights the importance of data security and the potential risks of compliance processes.

    Why it matters

    This incident underscores vulnerabilities in data handling practices across the fintech sector, raising concerns about customer privacy and security.

    What happened (in 30 seconds)

    • On September 12, 2026, Revolut disclosed sensitive customer data to scammers posing as a legitimate Italian government agency.
    • Approximately 680 customers, primarily high-net-worth individuals, were affected, with data including passports and transaction histories released.
    • Scammers initiated an extortion campaign, threatening to leak more data unless payments were made.

    The context you actually need

    • Revolut is a leading fintech unicorn, known for its rigorous KYC (Know Your Customer) and compliance procedures, which require extensive customer data collection.
    • Social engineering attacks targeting financial institutions have surged, exploiting weaknesses in email authentication and compliance processes.
    • Previous data leaks in Europe have highlighted systemic vulnerabilities in how fintech firms manage and protect customer data.

    What's really happening

    On or around September 12, 2026, Revolut, Europe's most valuable fintech startup, fell victim to a sophisticated social engineering attack. Scammers submitted fraudulent requests for sensitive customer data using a legitimate email domain associated with an Italian government agency. This domain passed authentication checks, leading Revolut's compliance team to mistakenly release sensitive information for approximately 680 customers. The data disclosed included full names, dates of birth, addresses, passports, driver's licenses, selfies, IBANs, statements, and crypto transaction histories.

    The incident did not involve a breach of Revolut's systems; rather, it exploited the company's compliance processes. Revolut's reliance on email verification and the authenticity of requests created a vulnerability that scammers were able to exploit. Once the data was released, the scammers launched an extortion campaign, threatening to leak more sensitive information unless they received payment. They utilized platforms like Telegram to communicate with victims and leaked samples of high-profile customer data to demonstrate their capabilities.

    In response to the incident, Revolut acted quickly to block the fraudulent email address and notified affected customers, law enforcement, and regulatory authorities. The UK Information Commissioner's Office has since initiated an investigation into the matter. Despite the incident, Revolut has stated that its systems and customer funds remain unaffected, although the reputational damage and scrutiny of its compliance protocols are significant.

    This incident highlights a growing trend in the fintech sector where social engineering attacks are becoming more sophisticated. As financial institutions increasingly rely on digital communication for compliance and customer verification, the risk of similar attacks is likely to rise. The incident serves as a wake-up call for fintech companies to reassess their data handling and compliance processes, ensuring they are robust enough to withstand such threats.

    Who feels it first (and how)

    • High-net-worth individuals: Likely to be targeted due to the value of their data.
    • Fintech companies: Increased scrutiny on compliance protocols and data security measures.
    • Regulatory bodies: Heightened focus on data protection regulations and enforcement.

    What to watch next

    • Regulatory responses: Watch for potential changes in data protection regulations as authorities react to this incident.
    • Market reactions: Monitor how this incident affects Revolut's valuation and customer trust in fintech services.
    • Emerging security measures: Look for innovations in data security and compliance processes within the fintech sector.
    Known:

    Revolut disclosed customer data to scammers via a legitimate email domain.

    Likely:

    Increased regulatory scrutiny and potential changes in compliance protocols across fintech firms.

    Unclear:

    The long-term impact on Revolut's customer trust and market position.

    Frequently Asked Questions

    Why it matters?
    This incident underscores vulnerabilities in data handling practices across the fintech sector, raising concerns about customer privacy and security.
    What happened (in 30 seconds)?
    On September 12, 2026, Revolut disclosed sensitive customer data to scammers posing as a legitimate Italian government agency. Approximately 680 customers, primarily high-net-worth individuals, were affected, with data including passports and transaction histories released. Scammers initiated an extortion campaign, threatening to leak more data unless payments were made.
    What's really happening?
    On or around September 12, 2026, Revolut, Europe's most valuable fintech startup, fell victim to a sophisticated social engineering attack. Scammers submitted fraudulent requests for sensitive customer data using a legitimate email domain associated with an Italian government agency. This domain passed authentication checks, leading Revolut's compliance team to mistakenly release sensitive information for approximately 680 customers. The data disclosed included full names, dates of birth, addres
    Who feels it first (and how)?
    High-net-worth individuals: Likely to be targeted due to the value of their data. Fintech companies: Increased scrutiny on compliance protocols and data security measures. Regulatory bodies: Heightened focus on data protection regulations and enforcement.
    What to watch next?
    Regulatory responses: Watch for potential changes in data protection regulations as authorities react to this incident. Market reactions: Monitor how this incident affects Revolut's valuation and customer trust in fintech services. Emerging security measures: Look for innovations in data security and compliance processes within the fintech sector.
    6 Articles
    WSJ Tech

    Europe’s Most Valuable Startup Gave Data to a Scammer. Now It Faces a Shakedown.

    Digital bank Revolut has come under scrutiny after it inadvertently provided sensitive customer data to individuals impersonating a government agency, resulting in a significant security breach. The data included identity information, contact details...

    Crypto News

    Revolut faces UK probe after 680 customers exposed

    Revolut has notified 680 customers of a significant data breach after scammers exploited a fraudulent government email account to obtain sensitive information, including passports, addresses, bank details, and Bitcoin records. This incident has raise...

    21 hours ago
    Read Full Article
    TechRadar

    Revolut sent identity data, contact details, and documents to hackers posing as a government agency

    Revolut has reportedly sent sensitive identity data, contact details, and documents to hackers who posed as a government agency, leading to a significant security breach. The company is now facing a substantial ransom demand to keep this information ...

    Cointelegraph

    Revolut attackers threaten daily customer data leaks

    Attackers have threatened Revolut with daily leaks of customer data, having already published identity documents and selfies of users, demanding payment to halt further disclosures. This incident highlights significant vulnerabilities in the fintech'...

    Cointelegraph

    Revolut says customer data exposed through fake government email

    Revolut has reported a significant data breach after customer information, including passports and financial transaction histories, was exposed due to a fraudulent request that appeared to come from a government agency. This incident has raised serio...

    The Arabian Post

    Revolut discloses customer data leak after email scam

    Revolut has reported a data leak affecting a limited number of customers, where sensitive personal and financial information was exposed due to fraudulent requests sent from an unauthorized email account that appeared to be from a legitimate governme...