About

The consultancy born at the intersection of behavioral economics and human experience.

NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

AI PRODUCTS

Opinion

Insights, research, and conversations at the frontier of CX.

ReadExperience JournalArticles & research on CX, behavior, and transformation.Watch & listenExperience LoomOur video podcast on CX & behavior.CuratedCX NewsIndustry news that matters in CX, minus the noise.

Latest articles

Latest episodes

Latest news

Hub

Free tools, templates, and resources to advance your CX practice.

NEW · MANIFESTO

Burn the Deck. Ten Virtues. Zero Excuses. — read our manifesto for the brave consultant.

Start reading →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

Digital Transformation · 13 September 2026

Revolut Confirms Data Breach via Fake Government Requests

Revolut has confirmed that attackers used fraudulent government requests to obtain customer data, and has notified affected customers, regulators and law enforcement.

Newsdesk
Curated briefing · 2 min read · 2 sources

What happened

Revolut has confirmed a data breach in which attackers used fraudulent government requests to obtain customer information. The digital bank said it has notified affected customers directly and has alerted the relevant government agency, law enforcement bodies and financial regulators about the incident.

Details of how the fake requests were constructed, how many customers were affected, or how long the exposure lasted have not been disclosed. Revolut's public confirmation follows what appears to be an internal investigation into the misuse of official-looking channels to extract customer data from the fintech.

Why it matters

Financial institutions routinely honour legitimate law enforcement and government data requests as part of regulatory compliance and public safety obligations. When bad actors successfully impersonate those channels, they exploit the very trust mechanisms that make such cooperation possible — turning a compliance process into an attack surface. For a digital-first bank like Revolut, whose entire value proposition rests on frictionless, app-based trust, this is a direct hit to the credibility of its data-handling practices.

For experience and risk leaders more broadly, the incident is a reminder that verification protocols for third-party and institutional requests deserve the same scrutiny as customer-facing authentication. Fraud has increasingly shifted from attacking front-end login flows to exploiting back-office and institutional trust relationships that customers never see — but pay the price for when they fail.

The Renascence take

Most coverage of this incident will focus on the breach mechanics. The more useful question for service and trust leaders is what it reveals about where organisations concentrate their defensive attention.

Firms pour enormous effort into hardening the customer-facing login screen while treating institutional and government-request channels as implicitly trustworthy back-office plumbing. That asymmetry is exactly what this incident exploited. A customer-obsessed operator should treat every data-release pathway — not just the ones customers interact with — as a trust surface requiring its own verification, escalation and audit trail. The real lesson isn't "improve cybersecurity" in the abstract; it's that trust architecture has to be designed end-to-end, including the parts of the organisation the customer never sees.

Sources

This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

FAQ

Questions we get on this topic

Revolut confirmed that attackers used fraudulent, official-looking government requests to obtain customer information, rather than exploiting a technical system vulnerability.

Revolut has not disclosed the number of affected customers, how the fake requests were constructed, or how long the exposure lasted.

Revolut has notified affected customers directly and alerted the relevant government agency, law enforcement bodies and financial regulators about the incident.

Because Revolut relies on frictionless, app-based trust, an attack that exploits institutional data-request channels rather than customer logins undermines confidence in its back-office data-handling practices.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.