Revolut Data Breach Affected 680 Customer Accounts

An unauthorized party used a spoofed government domain to extract sensitive customer data from the fintech firm.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration showing a stone plinth with a central fissure, surrounded by geometric pillars, representing a data security failure.
Revolut confirmed a data breach affecting 680 customer accounts after employees responded to fraudulent data requests from a spoofed government email domain. AI Illustration. Upload story photo >

Live Poll

Do you trust fintech companies to keep your sensitive personal and financial information secure?

Revolut has confirmed a data breach involving 680 customer accounts across 33 countries. The incident occurred when company personnel provided account information in response to fraudulent data requests sent from a legitimate government email domain.

Why it matters

The breach highlights the persistent risk of social engineering attacks that exploit trust in official communication channels. By targeting the human element of security, attackers bypassed standard system defenses to access sensitive user documentation.

The incident involved the unauthorized exposure of 680 individual records, which reportedly include customer names, physical addresses, account details, and verification photos. While these records were disclosed, the company maintains that its primary banking infrastructure and total customer funds remained secure.

The players

Revolut

A global fintech company providing digital banking, currency exchange, and cryptocurrency trading services through a mobile application stack.

The details

The breach was orchestrated through a social engineering attack where an unauthorized third party leveraged a spoofed government agency email domain. Employees, believing the requests were mandatory legal directives, released customer data to the attackers. Once the information was obtained, the threat actors reportedly released samples of the stolen documentation and began using the data to issue blackmail threats.

Timeline

  1. July 2026: Blackmail threats targeting customers were reported by a crypto entrepreneur.

  2. September 2026: The data breach incident emerged publicly.

The Tech Race

This breach underscores the shift from direct system exploitation to sophisticated social engineering as the primary vector for data theft in fintech. The reliance on spoofed institutional domains marks a departure from traditional brute-force attacks and signals a focus on subverting organizational trust processes.

Impacted customers in the 33 affected countries may face an increased risk of phishing or extortion attempts using their stolen verification photos and addresses. Those concerned about their security should monitor their financial accounts and exercise heightened caution regarding unsolicited communications referencing their identity.

The takeaway

The event serves as a reminder that verification photos and personal addresses are high-value targets for threat actors seeking to facilitate long-term identity theft. Users should watch for any official correspondence from the company regarding specific steps to secure accounts or potential identity monitoring services.

Further reading

For broader context on how organizations are defending against social engineering, visit the Cybersecurity section.

Live Poll

Do you trust fintech companies to keep your sensitive personal and financial information secure?

Revolut Data Breach Affected 680 Customer Accounts