Revolut gave customer IDs and financial data to a government impostor

Imported from official source

Cybersecurity Classified by Officially

Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain, according to TechCrunch.

Revolut is a London-based banking and financial platform with more than 80 million customers globally, according to the company.

Revolut describes this as an external impersonation scam, not an intrusion into its systems. It also says customer funds were not affected. Revolut has not identified the government agency or disclosed its email domain.

The attacker appears to have abused the trust attached to a real government email domain to make bogus requests for customer information. Revolut detected the activity, blocked the sending address, and says it notified the relevant agency, law enforcement, data protection authorities, and financial regulators.

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”

Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:

  • Identity and contact information like dates of birth, postal address, email address, and phone number.
  • Copies of IDs such as passports and driver’s licenses.
  • Verification selfies.
  • Account statements and transaction histories.

Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.

Those customers have received or will receive an email specifying which of their personal data was disclosed:

How to stay safe

The likely consumer impact will be second-stage fraud attempts rather than immediate unauthorized transfers. Here are some guidelines to help keep your money safe:

This is an extract. The publication continues at the source.

Read the original at the source: https://www.malwarebytes.com/blog/news/2026/09/revolut-gave-customer-ids-and-financial-data-to-a-government-impostor

Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Malwarebytes — imported from official source
Official source
https://www.malwarebytes.com/blog/feed/index.xml RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://www.malwarebytes.com/blog/news/2026/09/revolut-gave-customer-ids-and-financial-...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.