Drooid Logo
Back to story perspectives

Full Breakdown

Revolut Data Breach Highlights Vulnerability of Government-Email Verification

By Drooid · · How we work

Core Event

In early September 2026 Revolut confirmed that an unauthorized third party obtained sensitive customer information after the fintech complied with fraudulent data-request emails that appeared to come from a legitimate government-agency domain. The breach was discovered after the company contacted the implicated agency and learned the request was not authentic. Revolut said its core systems and customer funds were not compromised.

Background & Context

Revolut, a London-based digital banking platform, serves more than 80 million customers across over 30 jurisdictions and holds banking licences in the United Kingdom and France. The firm is pursuing a “lean bank” licence from the Bank of Israel and, on September 3, received conditional approval from the U.S. Office of the Comptroller of the Currency for a national-bank charter.

Timeline

  • September 11, 2026 – A customer-notification email circulated, describing the fraudulent request as having passed valid domain-authentication checks.
  • September 12, 2026 – Revolut issued a public statement confirming the incident, detailing the data types exposed, and describing the steps taken to block the email address and notify authorities.
  • September 3, 2026 – The OCC granted conditional approval for Revolut’s U.S. bank charter, coinciding with heightened scrutiny of the firm’s data-handling practices.

Data & Statistics

  • Exposed data includes full legal names, dates of birth, residential and email addresses, phone numbers, scanned passports and driver’s licences, verification selfies, account statements, IBANs, withdrawal records, and transaction histories—including Bitcoin activity.
  • Revolut described the impact as affecting a “very limited” number of customers but did not disclose an exact figure.
  • The company’s customer base totals roughly 80 million users worldwide, operating in more than 30 countries.

Official Statements & Responses

Revolut’s spokesperson called the incident a “sophisticated external impersonation scam” using a genuine government-agency email address. The firm blocked the offending address, alerted the agency, and notified law-enforcement, data-protection authorities, and regulators. It also contacted the limited number of affected individuals to offer support and confirmed that internal systems and funds were untouched.

Security researcher ZachXBT, who first publicised the breach, suggested the attack may have targeted high-net-worth users, though this has not been verified. Analyst Max Karpis later clarified that a circulating rumor about a security employee being fired was satirical and unrelated.

Conflicting Reports & Gaps

  • Number of affected customers: Described as “limited” but no specific count provided.
  • Geographic scope: Unclear whether the breach was confined to a single market or spanned multiple jurisdictions.
  • Government agency identity: The specific agency whose domain was spoofed has not been identified.
  • Extent of data per customer: The notification listed many data types, but exact records per individual were not detailed.

Outlook

European data-protection regulations require firms to notify supervisory authorities within 72 hours of a breach and to inform affected individuals when the risk is high. Revolut asserts compliance with these obligations. Ongoing investigations by law-enforcement and data-protection bodies will determine whether additional regulatory measures are imposed as the company advances its Israeli “lean bank” licence application and prepares for a U.S. national-bank launch.