Revolut has confirmed that it disclosed sensitive customer data to an unauthorised third party after receiving fraudulent information requests sent from an email account operating inside a real government agency's domain, in a customer notification that began circulating on 11 September 2026 and was reviewed by TechCrunch. The company's notification states that the communication carried valid domain authentication credentials and was therefore "fulfilled under the reasonable belief that it was an authentic government agency request" โ the impersonation defeated the sender-authentication checks that are supposed to establish that a message genuinely originates from an authority.
The disclosed material covers full name, date of birth and occupation; postal address, email address and telephone number; a copy of the customer's identity document, either passport or driver's licence; and the facial verification image supplied at onboarding. Revolut says the data may also have included account statements and transaction histories, with multiple outlets reporting the transaction data covered Bitcoin, and it has stated specifically that no biometric facial telemetry was involved. The company blocked the email address after discovering the scam, alerted the relevant government agency, law enforcement and financial regulators, and says its systems and customer funds are unaffected.
The significance is structural rather than volumetric: what left the building is the complete identity-verification package a regulated fintech is obliged to collect, assembled and delivered in a single response to an authority-looking request. The control that failed is one of the few integrity checks an organisation typically applies to inbound government correspondence, and it is a control that a spoofed message which passes domain authentication cannot defeat on its own. Crypto researcher ZachXBT surfaced the notification publicly on 11 September.
| Attribute | Detail |
|---|---|
| Sector | Financial Services |
| Date | 2026-09-14 |
| Source | TechCrunch |
| Reliability | Tier 2 |
| Breach class | Confirmed breach โ victim disclosure |