# Revolut Data Breach Exposes Sensitive Customer Information

*Published September 16, 2026*
*Source: [https://www.infosecurity-magazine.com/news/revolut-data-breach-fake-government/](https://www.infosecurity-magazine.com/news/revolut-data-breach-fake-government/)*

## Executive Summary

Revolut experienced a data breach where fraudsters used fake government requests to access sensitive customer information. The breach highlights the need for stringent verification controls in financial institutions to prevent identity fraud and phishing risks.

## Article

Revolut, a prominent British fintech company, has confirmed a data breach that exposed sensitive customer information through a sophisticated impersonation scam. The breach involved fraudsters who submitted fake information requests using a legitimate government agency email domain. These requests were processed by Revolut employees as part of normal legal compliance procedures. Although the breach affected only a limited group of customers, the compromised data is extensive, including personal identification details such as full names, dates of birth, and residential addresses. Additionally, copies of government ID documents and financial information, including IBANs and transaction histories, were accessed. 

Upon discovering the breach, Revolut's security team quickly blocked the fraudulent address, informed affected customers, and notified both the relevant government agency and enforcement bodies. The company assured the public that its systems and customer funds remain secure, yet the nature of the exposed data poses risks of identity fraud and phishing attacks. Security experts underscore the need for rigorous verification controls at fintech firms handling sensitive data. 

Revolut has advised customers to be vigilant against potential scams and to verify any communications claiming to be from the company or other organizations. Customers are urged to avoid sharing passwords or one-time security codes and to use Revolut's official app or website for any interactions. The company also recommends using multi-factor authentication, unique passwords, and monitoring accounts for any suspicious activity.
