Today: September 23, 2026
September 15, 2026
1 min read

Revolut Exposes Personal Data of Hundreds of Customers After Fake Government Request

Hundreds of Revolut customers have had sensitive personal information exposed after online fraudsters used a legitimate government email address to send fake requests for customer data to the financial technology company. The incident, which came to light in September 2026, involved an unauthorized third party impersonating a government agency and convincing Revolut to provide information that should have been protected. The exposed data may have included names, dates of birth, addresses, telephone numbers, copies of passports and driving licenses, verification photographs, account statements and transaction histories, including information related to Bitcoin activity. Revolut has contacted affected customers and notified regulators and law enforcement.

The incident is particularly notable because the attackers apparently did not need to break into Revolut’s systems. Instead, they exploited the trust normally associated with official government communication. The fraudsters used an email address belonging to the legitimate domain of an unnamed government agency and sent requests that appeared to be official. Revolut accepted the requests and handed over sensitive customer information before discovering that they were fraudulent. The company has described the incident as a sophisticated external impersonation scam and said it blocked the email address after identifying the problem. Revolut also stressed that its systems and customer funds were not affected by the incident.

While Revolut has not publicly confirmed the number of affected customers, sources familiar with the investigation told the Financial Times that the company had contacted around 680 people believed to have been affected. One of those customers was Mark Karpelès, the former chief executive of Mt. Gox, once the world’s largest Bitcoin exchange. Karpelès said Revolut contacted him about the incident on September 12 and informed him that his information had been among the data exposed. The incident has raised questions about how financial companies verify requests for sensitive information, particularly when those requests appear to come from legitimate government addresses.

The information potentially exposed goes well beyond basic customer details. According to information provided to affected customers, the data may have included account statements, IBANs, withdrawal records and complete transaction histories, alongside identity documents and verification information. This creates a potentially valuable collection of information for criminals because personal identity details combined with financial activity can be used in further fraud attempts or targeted scams. Revolut has said it notified the relevant government agency, law enforcement authorities, data protection authorities and financial regulators after discovering the incident.

The case highlights a broader challenge facing digital banks and financial technology companies as more consumers move their banking activity online. Revolut, founded in 2015, has grown into one of Europe’s largest digital financial services companies, with around 80 million customers globally. The company also has a significant presence in Slovenia, where local reports say it has more than 230,000 users. The incident demonstrates that cybersecurity threats do not always involve sophisticated attacks against databases or banking infrastructure. Sometimes, criminals can exploit something much simpler: the assumption that an email coming from a trusted government domain must also represent a genuine request.

Previous Story

West Nile Fever Spreads Across Serbia as 43 Cases Are Recorded

Next Story

Slovenia Marks Primorska Holiday as Debate Over Its Name Continues

Latest from Blog

Go toTop