Blog

Revolut Confirms Data Breach Following Fake Government Requests

Written by doudou - September 25, 2026

← All articles

What happened?

Revolut, the British fintech company specializing in digital banking services, recently confirmed that it had been the victim of a data breach after a fraudster used a fake government request to deceive employees.

According to a report by TechCrunch, the attacker allegedly used an email address belonging to a legitimate government domain to lend more credibility to his requests and obtain information about certain customers.

What data was exposed?

The data in question would include, in particular:

  • Name, last name

  • Date of Birth

  • Address

  • Number

  • Copies of passports

  • Copies of driver's licenses

  • Selfies Used for Identity Verification

  • Account Information

  • Transaction History

Revolut states that only a limited number of customers are affected by the incident.

Revolut Responds Quickly

After discovering the fraud, Revolut says it has blocked the address used by the attacker.

The company also notified the relevant authorities to follow up on the investigation.

Revolut also states that customer funds and its systems remain secure and that the incident did not compromise users' accounts or money.

A social engineering attack

This case shows that a cyberattack does not necessarily require technical vulnerabilities. In this instance, the attacker exploited the employees’ trust by posing as a government agency. Here, instead of directly hacking into a computer system, the cybercriminal attempts to manipulate a person into voluntarily providing the desired sensitive information.

Why This Case Is Important

Financial companies (in this case, Revolut) have numerous technical safeguards in place to secure their customers’ accounts. However, no security measure is foolproof! Employees also remain a major target for cybercriminals. This incident serves as a reminder that it’s essential to know who you’re dealing with—and, above all, never to give out your personal information to just anyone!

What should customers do?

Stay extra vigilant when it comes to suspicious emails, text messages, or calls—even if they appear to be “OFFICIAL”!
And remember to avoid sharing your passwords, security codes, or banking information whenever possible in response to an unexpected request. You never know who’s behind it! If you receive a suspicious message claiming to be from Revolut or a government agency, it’s best to contact the organization directly through its official channels, such as their customer service number or email address!

Key Takeaways

This data breach highlights an often-underestimated risk: even when an IT system is properly secured, a social engineering attack can allow a fraudster to obtain the sensitive information they want!

Revolut says it has taken steps to block the attack and protect its customers!

Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.