Data breach at Revolut following fraudulent government requests
The incident was detected prior to 12 September 2026, when Revolut identified fraudulent requests for information sent from the legitimate email domain of a government agency. The company has not specified when the incident began or for how long these requests were sent.
An unauthorised third party used that domain to request customer data. The exposed information may have included personal and contact details, identity documents, verification photographs, account statements and transaction histories. Revolut blocked the address used, notified the relevant authorities and regulators, and contacted those affected.
Revolut stated that its systems and customers’ funds were not affected. On 16 September, the company noted that it had not received any direct contact or ransom demand from those claiming to be behind the incident. The identity of those responsible, the final number of people affected and the outcome of the investigation had not been publicly confirmed.
-
15/09/2026Financial Times
-
17/09/2026The Guardian


