Revolut Gave Customer Data to Scammers Using Government Domain

In Data Breach News, Finance
September 12, 2026

Revolut is a global digital banking and fintech platform that is headquartered in the U.K. And to their embarrassment, they handed over personal and sensitive customer data to scammers who used a government email domain to trick them. HackRead reports:

The incident did not involve attackers breaching Revolut’s systems. Instead, the fraudulent requests came from an unauthorized email account using the government agency’s official domain and carried valid domain authentication credentials.

Revolut said it fulfilled the requests under the belief that they were authentic government requests. The company later contacted the government agency to verify the requests, which led to the discovery that the email account was unauthorized.

The types of information included passports, verification selfies, IBANs, and Bitcoin transaction records.

Read more at HackRead.