Mon, 14 Sept 2026
In the News

Revolut reveals data breach tied to counterfeit government requests

UnbarNewsUpdated 12 Sept 2026· 2 min read

The fintech firm says a phishing scam posing as official inquiries accessed customer information and prompted alerts to regulators and law enforcement.

Revolut reveals data breach tied to counterfeit government requests

Revolut has confirmed that a sophisticated phishing operation, which masqueraded as a government inquiry, succeeded in obtaining personal data belonging to a subset of its users. The company said the fraudulent request appeared to come from a legitimate authority, prompting some customers to share sensitive details before the deception was uncovered.

According to TechCrunch, Revolut promptly informed the affected account holders and reported the incident to the appropriate government agency, as well as to law‑enforcement bodies and financial regulators. The firm is also working with cybersecurity experts to assess the full scope of the breach and to reinforce its verification processes for any future external requests.

Revolut, founded in 2015, has grown into one of Europe’s largest digital banking platforms, serving millions across the United States, the United Kingdom and other markets. While the company has generally been praised for its rapid rollout of features, it has faced occasional security challenges, including a 2023 incident where a bug exposed transaction histories to a limited number of users. Phishing attacks that impersonate government entities are a well‑documented threat to fintech firms, as scammers exploit the trust users place in official communications to harvest login credentials and personal identifiers.

The breach arrives at a time when regulators in both the U.S. and the U.K. are tightening oversight of digital‑banking services. Under the EU’s GDPR and the U.S. state‑level data‑privacy statutes, firms must notify individuals and authorities within tight timeframes after discovering a breach. Revolut’s swift notification aligns with these obligations, but the episode underscores the ongoing tension between rapid product innovation and robust security controls.

Customers have been advised to monitor their accounts for unusual activity, reset passwords, and be wary of unsolicited requests that claim to be from government bodies. Industry analysts note that the incident may prompt other fintech providers to review their procedures for handling third‑party inquiries, potentially leading to broader adoption of multi‑factor authentication and stricter verification of external communications.

The episode serves as a reminder that even well‑funded, high‑profile fintechs are vulnerable to social‑engineering attacks, and that user vigilance remains a critical line of defense against data compromise.

This report is based on original reporting by TechCrunch. Read the original source →

#Revolut#data breach#cybersecurity#fintech#United States