Revolut Data Breach Exposed by Fake Government Requests, Customers Notified

Revolut Data Breach Exposed by Fake Government Requests, Customers Notified

TL;DR

  • Revolut confirmed attackers used forged government and law enforcement data requests to trick staff into sharing customer information.
  • Exposed data includes names, contact details and limited account metadata, but Revolut says no funds, passwords, PINs or full card details were taken.
  • Revolut has notified affected customers, UK and EU regulators, and law enforcement, and says it has tightened its legal request verification process.

How The Attack Happened

Revolut has confirmed a customer data breach stemming not from a hack of its core banking systems, but from carefully crafted fake government requests.

According to the company, threat actors posed as law enforcement and government agencies to submit fraudulent legal information requests. These types of requests, often used for urgent criminal investigations, typically demand fast turnaround and bypass normal customer notification, which the attackers exploited to create pressure.

Revolut said the forged requests looked legitimate, using spoofed official domains, agency letterheads, and references to real-sounding case numbers. In at least some cases, they appear to have originated from previously compromised third-party government email accounts, making initial detection far more difficult.

The requests were routed to internal teams that handle legal and compliance disclosures. Believing they were complying with lawful obligations, staff released limited customer information before secondary checks flagged inconsistencies in the documentation and follow-up communications.

Once the deception was discovered, Revolut revoked the disclosures, blocked the sender infrastructure, and launched a full internal review with external cybersecurity forensics support.

What Customer Data Was Exposed

Revolut stressed that its trading, banking and app login infrastructure was not breached, and customer funds remain safe.

The data shared in response to the fake requests varied by individual, but the company confirmed it was limited to identifying and account metadata. This includes full names, email addresses, phone numbers, residential addresses, and in some cases, account creation dates, account type, and limited transaction metadata.

Critically, Revolut said the incident did not expose account passwords, PINs, biometric data, full card numbers, CVVs, or seed phrases for crypto wallets. No ability to move money or take over accounts was granted through the information disclosed.

Still, security experts warn that even basic personal data can be weaponized for highly convincing phishing, SIM-swap attempts, and impersonation scams, especially when combined with knowledge that the victim is a Revolut customer.

The company has not yet disclosed the exact number of customers affected, but described it as a small subset of its more than 50 million global user base.

How Revolut Notified Affected Users

Revolut said it began notifying impacted customers directly via in-app alerts and email once the scope was confirmed.

The notifications explain what happened, what specific categories of data were involved for that user, and what Revolut is doing about it. The company emphasized it will never ask customers to transfer funds, share one-time passcodes, or provide full login credentials in response to the incident.

Affected users are being offered enhanced fraud monitoring, guidance on recognizing phishing, and access to dedicated support channels. Revolut is also urging all customers to turn on two-factor authentication, be wary of calls or messages claiming to be from Revolut or police, and verify any communication through the official app chat.

The fintech said it moved quickly to contain the issue before going public, to avoid tipping off the attackers while it preserved evidence and identified all fraudulent requests.

Regulators And Law Enforcement Response

Beyond customer notifications, Revolut confirmed it has reported the incident to relevant law enforcement agencies in the UK and Europe, and is cooperating with ongoing criminal investigations.

On the regulatory side, the company said it has informed financial regulators including the UK Financial Conduct Authority, the Bank of Lithuania which supervises its EU operations, and data protection authorities including the UK Information Commissioner's Office and Lithuanian counterparts.

Revolut said it is also reviewing its Law Enforcement Response procedures across all markets. New measures include mandatory multi-person approval for all government data disclosures, direct callback verification to known agency contacts over trusted channels, and stricter authentication for legal request portals.

The incident highlights a growing industry-wide trend of attackers abusing emergency data request processes, a tactic previously seen targeting major tech and crypto platforms.

What Customers Should Do Now

Security researchers recommend that all Revolut users, not just those notified, stay on high alert in the coming weeks.

Be skeptical of any unsolicited contact claiming to be from Revolut, police, or a government agency, especially if it references the breach and demands urgent action. Do not click links in unexpected texts or emails, and always open the Revolut app directly to check for alerts.

Customers should also monitor their accounts for unusual login attempts, update passwords if reused elsewhere, enable biometric and two-step verification, and consider placing extra fraud alerts with their mobile carrier to reduce SIM-swap risk.

Revolut says no action is needed regarding funds themselves, but anyone who believes they have been targeted as a result of the breach should contact support immediately through the in-app chat and report suspected fraud to local police.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
Revolut Data Breach Exposed by Fake Government Requests, Customers Notified Revolut Data Breach Exposed by Fake Government Requests, Customers Notified Reviewed by Randeotten on 9/12/2026 11:46:00 PM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.