Revolut Confirms Customer Data Breach: Third Party Impersonated Government Email to Obtain Sensitive Information

Revolut Confirms Customer Data Breach: Third Party Impersonated Government Email to Obtain Sensitive Information

2026-09-12 14:43View Original

It was reported that the UK-based fintech company Revolut confirmed a customer data breach, where an unauthorized third party exploited legitimate government agency domain email addresses to submit fraudulent information requests, resulting in the exposure of sensitive customer information. The leaked data includes identity and contact details such as date of birth, postal and email addresses, phone numbers, as well as copies of identity documents like passports and driver’s licenses; verification selfies, account statements, and transaction histories may also have been compromised.

Revolut stated the number of affected customers is "limited," and has directly notified relevant customers, though it did not disclose the exact figure or specify whether the incident was confined to particular markets, nor would it reveal the involved government agency. The company said it has blocked the associated email addresses and informed government bodies, law enforcement, and financial regulators, emphasizing that its systems and customer funds remain unaffected. Revolut serves over 80 million customers globally and operates banking services in more than 30 countries. Cryptocurrency security researcher ZachXBT noted that the incident appears to target high-net-worth individuals.

#AI Data and Privacy

Disclaimer: Contains third-party opinions, does not constitute financial advice

Recommended Reading

Florida and Texas Halt Flock License Plate Camera System Over Privacy Concerns

11 days ago
Florida and Texas Halt Flock License Plate Camera System Over Privacy Concerns

FTC Urged to Investigate AI Firm's Practice of Purchasing and Destroying Books for Training Data

21 days ago
FTC Urged to Investigate AI Firm's Practice of Purchasing and Destroying Books for Training Data

Attackers leveraged a single infrastructure to continuously exfiltrate data from Salesforce and ServiceNow customer portals for over a year

24 days ago
Attackers leveraged a single infrastructure to continuously exfiltrate data from Salesforce and ServiceNow customer portals for over a year

Open VSX removes 77 counterfeit extensions, some of which could expose development environments and repository information

08-05
Open VSX removes 77 counterfeit extensions, some of which could expose development environments and repository information

Mocha CEO Records Children's Bedtime Conversations into Claude to Generate Family Website, Sparking Privacy Controversy

08-05
Mocha CEO Records Children's Bedtime Conversations into Claude to Generate Family Website, Sparking Privacy Controversy

EFF Finds Android App Defaults Share User's Precise Location Data with Advertisers via SDK

08-05
EFF Finds Android App Defaults Share User's Precise Location Data with Advertisers via SDK

Apple Says More Former Employees May Have Taken Confidential Information to OpenAI, Seeks Temporary Injunction

08-05
Apple Says More Former Employees May Have Taken Confidential Information to OpenAI, Seeks Temporary Injunction