Digital Transformation · 13 September 2026
Revolut Confirms Data Breach via Fake Government Requests
Revolut has confirmed that attackers used fraudulent government requests to obtain customer data, and has notified affected customers, regulators and law enforcement.
What happened
Revolut has confirmed a data breach in which attackers used fraudulent government requests to obtain customer information. The digital bank said it has notified affected customers directly and has alerted the relevant government agency, law enforcement bodies and financial regulators about the incident.
Details of how the fake requests were constructed, how many customers were affected, or how long the exposure lasted have not been disclosed. Revolut's public confirmation follows what appears to be an internal investigation into the misuse of official-looking channels to extract customer data from the fintech.
Why it matters
Financial institutions routinely honour legitimate law enforcement and government data requests as part of regulatory compliance and public safety obligations. When bad actors successfully impersonate those channels, they exploit the very trust mechanisms that make such cooperation possible — turning a compliance process into an attack surface. For a digital-first bank like Revolut, whose entire value proposition rests on frictionless, app-based trust, this is a direct hit to the credibility of its data-handling practices.
For experience and risk leaders more broadly, the incident is a reminder that verification protocols for third-party and institutional requests deserve the same scrutiny as customer-facing authentication. Fraud has increasingly shifted from attacking front-end login flows to exploiting back-office and institutional trust relationships that customers never see — but pay the price for when they fail.
The Renascence take
Most coverage of this incident will focus on the breach mechanics. The more useful question for service and trust leaders is what it reveals about where organisations concentrate their defensive attention.
Firms pour enormous effort into hardening the customer-facing login screen while treating institutional and government-request channels as implicitly trustworthy back-office plumbing. That asymmetry is exactly what this incident exploited. A customer-obsessed operator should treat every data-release pathway — not just the ones customers interact with — as a trust surface requiring its own verification, escalation and audit trail. The real lesson isn't "improve cybersecurity" in the abstract; it's that trust architecture has to be designed end-to-end, including the parts of the organisation the customer never sees.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in Digital Transformation
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.