Financial tech and banking company Revolut released sensitive customer data, including copies of passports, verification selfies and full transaction histories after receiving a fraudulent request that seemed to be from a government agency.
Revolut says customer data exposed through fake government email
Passports, selfies and financial transaction histories of some customers were revealed to a fraudster using a government agency domain.
Cointelegraph by Michael Millard
Publisher Cointelegraph
Sep 13, 2026 at 9:27 AM UTC · 1 min de lectura

Requests for customer information sent from a legitimate government agency email domain passed Revolut’s authentication checks, according to International Cyber Digest posting on X. Revolut later concluded they were not authentic, and customers whose information was compromised were notified on Friday.
A company spokesperson told Cointelegraph on Saturday that “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
The spokesperson added that upon detection, Revolut blocked the address and alerted the relevant government agency. It also notified enforcement agencies and financial regulators.
Related: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long
“Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support,” the spokesperson said.
Market Context
Bitcoin
BTC
$77,814
+0.92% (24H)
Market Cap
$1.56T
Circulating Supply
20.1M BTC
24H Volume
$20.3B
24H High
$77,839
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
