Revolut has confirmed a data breach affecting a limited number of customers after fraudulent requests impersonated a government agency.
The UK-based fintech said on Saturday, 12 September 2026, that sensitive customer information had been disclosed to an unauthorised third party after it received fraudulent requests sent from what appeared to be a legitimate government agency email domain. In a statement, the company said the breach affected a ‘very limited’ number of customers, all of whom have been notified, though it did not disclose the exact number of individuals involved.
Nature of the breach and company response
According to the announcement, the incident did not compromise its systems or customer funds. A company spokesperson said that upon detection, the fraudulent email address was immediately blocked, and the relevant government agency was alerted alongside law enforcement, data protection, and financial regulators.
Data compromised in the breach reportedly included customers' dates of birth, postal and email addresses, and phone numbers, as well as copies of identity documents such as passports and driver's licenses. The incident illustrates a growing category of fraud in which attackers exploit trusted institutional email domains, including those of government bodies, to bypass standard verification procedures used by financial services firms when responding to official data requests.
Context: IPO plans and market position
The breach comes as Revolut prepares for a potential public listing, with the company reportedly aiming for a valuation of up to around EUR 172 billion, according to earlier Reuters reporting from April 2026. Revolut is considered one of the most successful European fintech companies, operating without physical bank branches and serving customers primarily through its mobile application.
The disclosure adds to scrutiny of how financial technology firms verify the authenticity of data requests purportedly originating from government or law enforcement bodies, an area of increasing concern as fraudulent impersonation tactics become more sophisticated. For a company preparing for a public listing, incidents involving customer data can carry reputational implications that extend beyond the immediate operational impact, particularly as identity verification documents were reportedly among the data exposed. Revolut has not disclosed further details on the scope of the breach or on any additional measures introduced following the incident.