top of page

🚨 Revolut Data Breach: Scammers Used a Real Government Email Domain to Obtain Customer Data

Writer: AigiShield
AigiShield
Sep 13
3 min read

Report date: September 13, 2026

Source classification: Verified Emerging Scam Alert

Scam type: Government impersonation, fraudulent data requests, identity-theft and follow-on phishing risk


What happened

Revolut confirmed on September 12 that it disclosed sensitive customer information to an unauthorized third party after fraudulent information requests arrived from an email address using a legitimate government-agency domain. Revolut described the incident as a sophisticated external impersonation scam and said only a very limited number of customers were affected.

According to Reuters and TechCrunch, information exposed in the incident included identity and contact data such as birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver’s licenses. TechCrunch reported that some customer notifications also referenced verification selfies, account statements, and transaction histories. Revolut said its systems and customer funds were unaffected.


How the scam works

This attack did not begin by tricking an ordinary consumer into clicking a fake login page. Instead, the attacker impersonated a government authority and used a legitimate government email domain to submit fraudulent requests for customer information to a financial company. That makes the incident especially important: familiar sender domains and apparently official credentials can sometimes be abused by criminals.

The stolen information can then create follow-on risk. Criminals with detailed identity, contact, financial, or transaction information may be able to craft highly convincing phishing messages, impersonate a bank or government agency, or attempt identity theft.


Who is targeted

Revolut says it directly notified the limited number of customers affected by this incident. More broadly, anyone whose identity documents, contact details, account information, or transaction history are exposed in a breach can face increased risk from targeted impersonation and phishing attempts.


Warning signs to watch for

  • Unexpected calls, texts, or emails that reference unusually specific personal or account information.

  • Someone claiming to be Revolut, a bank, law enforcement, or a government agency asking you to verify sensitive information or move money.

  • Messages that create urgency because of a supposed security incident, frozen account, investigation, or unauthorized transaction.

  • Requests for passwords, one-time verification codes, recovery phrases, copies of identity documents, or remote access to your device.

  • Links in breach-related messages that ask you to sign in instead of directing you to open the company’s known app or website yourself.


What consumers should do

  • If Revolut tells you that you were affected, verify the notice by opening the Revolut app or independently contacting the company rather than using contact details supplied in an unexpected message.

  • Treat future messages that quote your personal information as potentially fraudulent. Knowing accurate details about you does not prove the sender is legitimate.

  • Review financial accounts and credit reports for activity you do not recognize.

  • Consider placing a credit freeze if identity-document information has been exposed. The FTC says freezes are free and can make it harder for an identity thief to open new credit in your name.

  • If you discover identity theft, use IdentityTheft.gov to create an FTC recovery plan and report the misuse.


Why this development matters

AigiShield considers this a significant emerging scam development because the attacker reportedly used a legitimate government-agency email domain to make a fraudulent information request appear authentic. Consumers are often told to inspect the sender address as a first line of defense, but this incident shows why identity verification must go beyond the visible domain or caller identity. It also creates a credible risk of highly personalized follow-on scams against affected customers.


Sources


AigiShield reminder

Think it might be a scam? Let AigiShield check it out for you.

Think Before You Click. Verify Before You Trust.

 
 
 

Recent Posts

See All

Comments


bottom of page