Revolut disclosed a data breach September 12, 2026 after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. The attacker requested PII via email using a government agency’s domain with valid domain authentication credentials.
Exposed data includes full name, date of birth, occupation, contact details, identity documents (passport/driver’s license), verification selfies, account statements, IBANs, withdrawal records, and transaction histories including Bitcoin activity.
Revolut told Reuters a “very limited” number of customers were affected. This is not a technical breach — no systems compromised. Attackers created or compromised a rogue account within an official government domain. Revolut discovered fraud by independently contacting the agency, which confirmed it had not made the request.
Revolut previously disclosed a breach affecting 50,150 customers in September 2022.