• Sep 14, 2026
  • 1 min read

Revolut Confirms Limited Data Breach After Sophisticated Fake Government Scam

The British neobank Revolut has confirmed there had been a limited customer KYC data breach after what it described as a “sophisticated external impersonation scam.”

The British neobank Revolut has confirmed there had been a limited customer KYC data breach after what it described as a “sophisticated external impersonation scam.” Highly convincing fraudulent information requests were sent from an unauthorized email account using a legitimate government agency domain.

The affected records included names, birth dates, postal and email addresses, phone numbers, and copies of passports or driving licences. Some customers’ verification selfies, account statements, and transaction records may also have been exposed, including IBANs, withdrawal records, and Bitcoin transactions.

Revolut said it had blocked the email address after identifying the fraud and promptly alerted the spoofed government agency. It also notified law enforcement, data protection authorities, and financial regulators, and directly contacted affected customers.

Only a limited number of customers were affected by the incident. Revolut has stressed that customer funds and its own systems remain unaffected. Further details, such as the exact scale of the scam, the spoofed agency’s identity, and whether the incident was confined to a particular country, have not yet been made public.

This incident demonstrates how increasingly sophisticated phishing and impersonation attempts are making fraudulent communications harder to distinguish from genuine requests. The growing sophistication of fraud underlines the importance for companies to use separate channels to verify who is truly sending requests for sensitive information.