REVOLUT has confirmed that a data breach exposed information belonging to a “very limited group of customers” after an unauthorised third party submitted fraudulent information requests from an email address using a legitimate government-agency domain. The requests had valid technical domain authentication and were processed by employees as routine legal-compliance requests. Revolut described the incident as a “sophisticated external impersonation scam”.
It said its systems and customer funds were not affected, but declined to give the number of customers involved or identify the relevant market or department.
Independent crypto-security researcher ZachXBT reported the incident on 12 September 2026, sharing a customer notification issued by Revolut the previous day. The records reportedly included names, dates of birth, addresses, phone numbers, email addresses and occupations, as well as copies of identity documents and verification selfies. ZachXBT also claimed that IBANs, account-opening dates, complete transaction and withdrawal histories, and Bitcoin wallet reference numbers were exposed.
Revolut said it blocked the address immediately after detecting the activity, notified affected customers and alerted the relevant government agency, law-enforcement bodies, data-protection authorities and financial regulators.
Security experts warned that the information could support identity fraud and targeted phishing, despite no reported access to customer funds. Affected users should be wary of unexpected messages claiming to come from Revolut, government agencies or other trusted organisations, and should not disclose passwords, passcodes or one-time codes. Revolut should be contacted only through its official app or verified website.