Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Revolut confirms data breach via government email impersonation scam

Published 14 September 2026

Revolut has confirmed it was deceived by scammers who used a legitimate government email domain to obtain sensitive customer data, including identity documents. The digital bank stated that a limited number of users were affected and have been contacted directly, but has not disclosed the scale of the breach, the specific agency impersonated, or the countries involved. The company said the incident involved a sophisticated external impersonation scam. Fraudsters submitted fraudulent requests for information using a genuine government agency email address, which Revolut treated as legitimate. The data obtained included copies of passports, driving licences, dates of birth, home addresses, email addresses, and phone numbers. Upon detection, Revolut blocked the email address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators. The company emphasized that its systems and customer funds remain unaffected. The breach is particularly significant in Ireland, where Revolut has approximately 3.4 million customers. The company has not confirmed whether it has notified the Irish Central Bank about the incident.

0:00 / 0:00