gg2
firstpost.com

Revolut confirms customer data breach

Archived — this story has rotated out of today’s deck. It is kept here in full.

The gist

Revolut confirmed customer data was disclosed after it received fraudulent requests from a government email domain.
The fintech says a limited number of customers were affected.

Background

Revolut is a London-based fintech with more than 80 million customers globally, operating as a bank in over 30 countries. The breach occurred as the company was in the final stages of talks with the Bank of Israel to obtain a license, and shortly after the US Office of the Comptroller of the Currency granted conditional approval for a US national bank. Revolut is also planning a potential public listing and aiming for a valuation of up to $200 billion.

How it unfolded

  1. Sep 12, 2026Revolut confirmed that sensitive customer information was disclosed to an unauthorized third party after it received fraudulent requests sent from a legitimate government agency email domain, a spokesperson told Reuters.
  2. Sep 12, 2026The compromised data included birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver's licenses, according to a TechCrunch report.
  3. Sep 12, 2026Revolut said in its notification to affected customers that verification selfies, account statements, and transaction histories may also have been at risk.
  4. Sep 12, 2026A Revolut spokesperson confirmed to TechCrunch that a 'limited' number of customers were impacted and said the company had contacted those customers directly; the exact number was not disclosed.
  5. Sep 13, 2026Haaretz reported the breach occurred just before Revolut's Israel launch, with the company in the final stages of talks with the Bank of Israel to obtain a license.

Who’s saying what

Official
Revolut said it immediately blocked the address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators, adding that its systems and customer funds are unaffected.
Expert
Crypto security researcher ZachXBT said the incident appears to have targeted high-net-worth users.
Public
One affected person shared the email received from Revolut on X, complaining that the breach came right after Revolut sent him a notification 'to provide a LOT of data or we will close your account in 20 days'.

Still unverified

The exact number of individuals affected was not disclosed by Revolut. Revolut did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved. The data may have also included verification selfies, account statements, and transaction histories, according to the firm's notification. ZachXBT said the incident appears to have targeted high-net-worth users.

Sources

See today’s stories in the app gg2 — free on the App Store