Revolut Exposed Customer Data to Scammers via Legitimate Government Email Domain

If you use fintech services, this incident highlights the importance of data security and the potential risks of compliance processes.
Why it matters
This incident underscores vulnerabilities in data handling practices across the fintech sector, raising concerns about customer privacy and security.
What happened (in 30 seconds)
- On September 12, 2026, Revolut disclosed sensitive customer data to scammers posing as a legitimate Italian government agency.
- Approximately 680 customers, primarily high-net-worth individuals, were affected, with data including passports and transaction histories released.
- Scammers initiated an extortion campaign, threatening to leak more data unless payments were made.
The context you actually need
- Revolut is a leading fintech unicorn, known for its rigorous KYC (Know Your Customer) and compliance procedures, which require extensive customer data collection.
- Social engineering attacks targeting financial institutions have surged, exploiting weaknesses in email authentication and compliance processes.
- Previous data leaks in Europe have highlighted systemic vulnerabilities in how fintech firms manage and protect customer data.
What's really happening
On or around September 12, 2026, Revolut, Europe's most valuable fintech startup, fell victim to a sophisticated social engineering attack. Scammers submitted fraudulent requests for sensitive customer data using a legitimate email domain associated with an Italian government agency. This domain passed authentication checks, leading Revolut's compliance team to mistakenly release sensitive information for approximately 680 customers. The data disclosed included full names, dates of birth, addresses, passports, driver's licenses, selfies, IBANs, statements, and crypto transaction histories.
The incident did not involve a breach of Revolut's systems; rather, it exploited the company's compliance processes. Revolut's reliance on email verification and the authenticity of requests created a vulnerability that scammers were able to exploit. Once the data was released, the scammers launched an extortion campaign, threatening to leak more sensitive information unless they received payment. They utilized platforms like Telegram to communicate with victims and leaked samples of high-profile customer data to demonstrate their capabilities.
In response to the incident, Revolut acted quickly to block the fraudulent email address and notified affected customers, law enforcement, and regulatory authorities. The UK Information Commissioner's Office has since initiated an investigation into the matter. Despite the incident, Revolut has stated that its systems and customer funds remain unaffected, although the reputational damage and scrutiny of its compliance protocols are significant.
This incident highlights a growing trend in the fintech sector where social engineering attacks are becoming more sophisticated. As financial institutions increasingly rely on digital communication for compliance and customer verification, the risk of similar attacks is likely to rise. The incident serves as a wake-up call for fintech companies to reassess their data handling and compliance processes, ensuring they are robust enough to withstand such threats.
Who feels it first (and how)
- High-net-worth individuals: Likely to be targeted due to the value of their data.
- Fintech companies: Increased scrutiny on compliance protocols and data security measures.
- Regulatory bodies: Heightened focus on data protection regulations and enforcement.
What to watch next
- Regulatory responses: Watch for potential changes in data protection regulations as authorities react to this incident.
- Market reactions: Monitor how this incident affects Revolut's valuation and customer trust in fintech services.
- Emerging security measures: Look for innovations in data security and compliance processes within the fintech sector.
Revolut disclosed customer data to scammers via a legitimate email domain.
Increased regulatory scrutiny and potential changes in compliance protocols across fintech firms.
The long-term impact on Revolut's customer trust and market position.
Frequently Asked Questions
- Why it matters?
- This incident underscores vulnerabilities in data handling practices across the fintech sector, raising concerns about customer privacy and security.
- What happened (in 30 seconds)?
- On September 12, 2026, Revolut disclosed sensitive customer data to scammers posing as a legitimate Italian government agency. Approximately 680 customers, primarily high-net-worth individuals, were affected, with data including passports and transaction histories released. Scammers initiated an extortion campaign, threatening to leak more data unless payments were made.
- What's really happening?
- On or around September 12, 2026, Revolut, Europe's most valuable fintech startup, fell victim to a sophisticated social engineering attack. Scammers submitted fraudulent requests for sensitive customer data using a legitimate email domain associated with an Italian government agency. This domain passed authentication checks, leading Revolut's compliance team to mistakenly release sensitive information for approximately 680 customers. The data disclosed included full names, dates of birth, addres
- Who feels it first (and how)?
- High-net-worth individuals: Likely to be targeted due to the value of their data. Fintech companies: Increased scrutiny on compliance protocols and data security measures. Regulatory bodies: Heightened focus on data protection regulations and enforcement.
- What to watch next?
- Regulatory responses: Watch for potential changes in data protection regulations as authorities react to this incident. Market reactions: Monitor how this incident affects Revolut's valuation and customer trust in fintech services. Emerging security measures: Look for innovations in data security and compliance processes within the fintech sector.
Tech business coverage, major deals, product launches, and Silicon Valley trends.
"WSJ’s tech section offers authoritative reporting on the intersection of technology and business, including exclusive industry analysis."
— A47 Editor
Europe’s Most Valuable Startup Gave Data to a Scammer. Now It Faces a Shakedown.
Digital bank Revolut has come under scrutiny after it inadvertently provided sensitive customer data to individuals impersonating a government agency, resulting in a significant security breach. The data included identity information, contact details...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Revolut faces UK probe after 680 customers exposed
Revolut has notified 680 customers of a significant data breach after scammers exploited a fraudulent government email account to obtain sensitive information, including passports, addresses, bank details, and Bitcoin records. This incident has raise...
Consumer tech news, reviews, and buying guides for gadgets and electronics.
"TechRadar is known for comprehensive buying advice, hardware reviews, and consumer tech news targeted at mainstream audiences."
— A47 Editor
Revolut sent identity data, contact details, and documents to hackers posing as a government agency
Revolut has reportedly sent sensitive identity data, contact details, and documents to hackers who posed as a government agency, leading to a significant security breach. The company is now facing a substantial ransom demand to keep this information ...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Revolut attackers threaten daily customer data leaks
Attackers have threatened Revolut with daily leaks of customer data, having already published identity documents and selfies of users, demanding payment to halt further disclosures. This incident highlights significant vulnerabilities in the fintech'...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Revolut says customer data exposed through fake government email
Revolut has reported a significant data breach after customer information, including passports and financial transaction histories, was exposed due to a fraudulent request that appeared to come from a government agency. This incident has raised serio...
English-language digital publication covering business, politics, technology, and current affairs.
"The Arabian Post mixes original and syndicated-style coverage with a broad regional and global business-news orientation."
— A47 Editor
Revolut discloses customer data leak after email scam
Revolut has reported a data leak affecting a limited number of customers, where sensitive personal and financial information was exposed due to fraudulent requests sent from an unauthorized email account that appeared to be from a legitimate governme...