Explanatory journalism with depth and rigorPTENES
Explosão SolarContext. Not just headlines.Search

Revolut Confirms Customer Data Leak After Email Fraud.

British fintech reveals unauthorized third parties obtained sensitive user information after receiving fraudulent requests.

Daniele Morais
September 15, 2026 · 2 min read
ShareWhatsAppXFacebook

Last week, fintech Revolut reported that customer information was handed over to an unauthorized third party after a fraudster used a legitimate government agency email address to request data. The case gained prominence when disclosed by international outlets, which indicate that some of the leaked documents are already circulating online.

How the Fraud Was Executed

According to the company's statement, an external attacker sent information requests using an email domain belonging to a recognized government agency. The message requested identity and contact details, as well as official documents, and was accepted as legitimate by Revolut's internal systems.

Types of Information Compromised

The disclosed data included full name, date of birth, residential and electronic addresses, phone numbers, copies of passports and ID cards, verification selfies, as well as account statements, transaction history, and, in some cases, bank account information and cryptocurrency transactions.

Revolut's Reaction

The company stated that it immediately blocked the email address used, notified the government agency involved, law enforcement authorities, and financial regulators. It also directly contacted affected customers to offer support, emphasizing that internal systems and user funds were not compromised.

Publication and Blackmail by Criminals

Groups on messaging apps disclosed excerpts of supposedly obtained documents, including passports of Dutch citizens. In parallel, the criminals demanded a ransom of 10,000 bitcoins – over US$780 million – threatening to release more information if the demand was not met.

Impact and Lessons for Users

Although Revolut did not disclose the exact number of victims, it acknowledged that the incident affected a limited number of customers, including high-net-worth users. The case highlights the vulnerability of processes that rely on emails from official domains without additional verification and reinforces the need for more robust authentication measures.

Fintech's Next Steps

In addition to strengthening email filters and validation procedures, Revolut stated that it will continue to collaborate with authorities to investigate the origin of the fraud and prevent new incidents. The company also emphasizes that it is moving forward with obtaining banking licenses in several countries, maintaining its focus on user data security.

With information from TechCrunch, NL Times, UA.NEWS.

Source: TechCrunch, NL Times, UA.NEWS

#revolut#data leak#cybersecurity#digital fraud#ransomware
Also inPortuguêsEspañol
ShareWhatsAppXFacebook