Revolut confirms customer data disclosure breach

Revolut confirms customer data disclosure breach

Revolut has confirmed customer data was disclosed through fraudulent requests. The fintech says its systems and customer funds were unaffected, but personal information and identity documents were exposed after requests arrived through a legitimate government-agency email domain.


Revolut has confirmed that sensitive customer information was disclosed to an unauthorised third party after fraudulent data requests were sent from an email domain belonging to a legitimate government agency.

The London-headquartered fintech said a “very limited” number of customers were affected and had been notified directly. It has not disclosed the number of people involved or identified the public body whose email domain was used.

The exposed information included dates of birth, postal and email addresses, telephone numbers, and copies of identity documents including passports and driving licences.

Revolut said its own technology infrastructure had not been penetrated. A spokesperson said: “Revolut systems and customer funds are unaffected.”

After identifying the fraudulent requests, the company blocked the relevant address and alerted the government agency involved, enforcement bodies, data-protection authorities, and financial regulators.

The episode exposes a security problem that differs from a conventional attack on banking infrastructure. Financial institutions routinely respond to lawful requests from police forces, courts, regulators, tax authorities, and other public bodies. The integrity of that process depends on staff being able to establish that a request is genuine before customer information is released.

A communication arriving through a legitimate institutional domain can carry an appearance of authenticity even when the person using it is not entitled to the information being requested. Controls around official data requests therefore sit alongside network security, access management, fraud detection, and customer authentication as part of a financial institution’s wider operational-resilience framework.

The sensitivity of the information held by regulated financial businesses increases the potential impact. Know-your-customer and anti-money-laundering requirements mean banks and fintech providers maintain detailed identity records that can include addresses, identification documents, transaction information, and other personal data needed to verify customers and monitor financial crime.

Identity information can retain value even where passwords, payment credentials, and account balances are unaffected. Names, dates of birth, contact details, and government-issued documents can be combined with information obtained elsewhere to support impersonation, social engineering, or subsequent fraud attempts.

The disclosure therefore places emphasis on the procedures used to authenticate third-party requests as well as the technical controls surrounding Revolut’s own systems.

The incident comes during a period of rapid international expansion for the UK-founded company. Revolut says it serves around 80 million customers globally and has continued to expand its regulated banking operations across multiple jurisdictions.

Earlier this month, the US Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a national bank in the United States. The company plans to invest about $95m in the proposed operation and is targeting a launch during the first half of 2027, subject to further regulatory approvals.

That growth increases the number of legal and supervisory systems the business must navigate. A multinational financial provider can receive official information requests from numerous government organisations, each operating under different laws, procedures, documentation standards, and timescales.

The operational challenge is to authenticate those requests without preventing or unnecessarily delaying lawful disclosure. Financial institutions have obligations to cooperate with authorised investigations involving areas such as fraud, sanctions, money laundering, tax enforcement, and other criminal activity.

Stronger checks therefore have to distinguish between legitimate requests and sophisticated impersonation rather than simply making information harder to obtain in every circumstance.

Governance expectations also rise as fintech companies mature into full banking organisations. Holding deposits and providing credit directly brings greater scrutiny of operational resilience, data governance, customer protection, financial-crime controls, incident management, and board oversight.

The Revolut disclosure illustrates how those responsibilities extend beyond the security perimeter of the institution itself. A bank can maintain the integrity of its internal systems while still losing control of customer information through a trusted external process.

The company has not publicly detailed how the fraudulent requests passed its verification procedures or whether those procedures have been changed. It has concentrated its response on contacting affected customers, blocking the communication route, and informing the relevant authorities.

Regulatory attention will now extend to how the requests were authenticated and whether additional safeguards are required around disclosures to external organisations. For banks and fintech businesses handling large stores of verified identity data, official communication channels increasingly require the same assumption of possible compromise that already applies to other parts of the security environment.



  • Burnham convenes business chiefs for growth talks

    Burnham convenes business chiefs for growth talks

    Andy Burnham will host major business leaders at Downing Street. Executives and entrepreneurs will discuss investment, infrastructure, innovation, and devolution as the government develops its growth programme ahead of major fiscal decisions.


  • Revolut confirms customer data disclosure breach

    Revolut confirms customer data disclosure breach

    Revolut has confirmed customer data was disclosed through fraudulent requests. The fintech says its systems and customer funds were unaffected, but personal information and identity documents were exposed after requests arrived through a legitimate government-agency email domain.


  • Oakley NAV grows as share price lags

    Oakley NAV grows as share price lags

    Oakley Capital Investments grew NAV despite weak listed-share performance overall. The portfolio returned 6% in the first half while shareholder returns fell 16%, keeping the investment company’s market discount firmly on the board agenda.